CVE-2017-16539: Infoleak
The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2017-16539.
What is the severity of CVE-2017-16539?
The severity of CVE-2017-16539 is medium with a CVSS score of 5.9.
How does CVE-2017-16539 affect Docker Moby?
CVE-2017-16539 affects Docker Moby versions up to and including 17.03.2-ce.
How can an attacker exploit CVE-2017-16539?
An attacker can exploit CVE-2017-16539 by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi, which can lead to data loss in certain older Linux kernels.
Is there a fix available for CVE-2017-16539?
Yes, there is a fix available for CVE-2017-16539. Users should upgrade to a fixed version of Docker Moby.