First published: Mon Apr 20 2020(Updated: )
The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.<br>Security Fix(es):<br><li> runc: volume mount race condition with shared mounts led to information leak and integrity manipulation (CVE-2019-19921)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/runc | <1.0.0-66.rc10.rhaos4.3.el7_8 | 1.0.0-66.rc10.rhaos4.3.el7_8 |
redhat/runc | <1.0.0-66.rc10.rhaos4.3.el7_8 | 1.0.0-66.rc10.rhaos4.3.el7_8 |
redhat/runc-debuginfo | <1.0.0-66.rc10.rhaos4.3.el7_8 | 1.0.0-66.rc10.rhaos4.3.el7_8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:1485 is classified as moderate.
To fix RHSA-2020:1485, update the runc package to 1.0.0-66.rc10.rhaos4.3.el7_8.
RHSA-2020:1485 affects the runc package used for container runtimes.
RHSA-2020:1485 addresses a volume mount race condition leading to information leak and integrity manipulation (CVE-2019-19921).
Yes, the specific version to look for in RHSA-2020:1485 is 1.0.0-66.rc10.rhaos4.3.el7_8.