First published: Sun Sep 02 2018(Updated: )
Google gVisor before 2018-08-23, within the seccomp sandbox, permits access to the renameat system call, which allows attackers to rename files on the host OS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google gVisor | <2018-08-23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16359 has been classified as a medium severity vulnerability due to the potential for file renaming on the host OS.
To fix CVE-2018-16359, upgrade to Google gVisor version 2018-08-23 or later.
CVE-2018-16359 affects Google gVisor versions prior to 2018-08-23.
CVE-2018-16359 can be exploited by attackers to rename critical files on the host operating system.
Yes, CVE-2018-16359 is a vulnerability within the seccomp sandbox of Google gVisor.