CVE-2018-20699: Medium severity docker vulnerability
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemonunix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-20699?
CVE-2018-20699 is a vulnerability in Docker Engine that allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value.
What is the severity of CVE-2018-20699?
CVE-2018-20699 has a severity rating of 4.9, which is considered medium.
How can CVE-2018-20699 be exploited?
CVE-2018-20699 can be exploited by providing a large integer in the --cpuset-mems or --cpuset-cpus value.
Is Docker Engine version 18.09 affected by CVE-2018-20699?
Yes, Docker Engine version 18.09 is affected by CVE-2018-20699.
How can I fix CVE-2018-20699?
To fix CVE-2018-20699, upgrade to a version of Docker Engine that is not affected by the vulnerability.