CVE-2016-0761: Critical severity cloudfoundry Garden Linux vulnerability
Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container files during Docker image preparation that could be used to delete, corrupt or overwrite host files and directories, including other container filesystems on the host.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0761?
CVE-2016-0761 has a medium severity rating due to potential data loss and system corruption.
How do I fix CVE-2016-0761?
To fix CVE-2016-0761, upgrade to Cloud Foundry Garden-Linux v0.333.0 or Elastic Runtime 1.6.17 or later.
What systems are affected by CVE-2016-0761?
CVE-2016-0761 affects Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime versions earlier than 1.6.17.
What is the impact of CVE-2016-0761?
The impact of CVE-2016-0761 includes the potential to delete, corrupt, or overwrite host files and directories.
Is there a workaround for CVE-2016-0761?
A temporary workaround for CVE-2016-0761 is to restrict access to the affected container management features until a patch can be applied.