REDHAT-BUG-1666565: Low severity docker vulnerability
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemonunix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
References:
https://github.com/docker/engine/pull/70 https://github.com/moby/moby/pull/37967
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1666565?
REDHAT-BUG-1666565 is classified as a denial of service vulnerability due to memory consumption in Docker Engine.
How do I fix REDHAT-BUG-1666565?
To fix REDHAT-BUG-1666565, upgrade Docker Engine to version 18.09 or later.
What systems are affected by REDHAT-BUG-1666565?
REDHAT-BUG-1666565 affects Docker Engine versions prior to 18.09.
What exploits are associated with REDHAT-BUG-1666565?
The exploit for REDHAT-BUG-1666565 involves supplying large integers in the --cpuset-mems or --cpuset-cpus parameters.
When was REDHAT-BUG-1666565 reported?
REDHAT-BUG-1666565 was reported in the context of vulnerabilities affecting earlier Docker Engine releases.