USN-4297-1: runC vulnerabilities
It was discovered that runC incorrectly checked mount targets. An attacker with a malicious container image could possibly mount over the /proc directory and escalate privileges. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-16884) It was discovered that runC incorrectly performed access control. An attacker could possibly use this issue to escalate privileges. (CVE-2019-19921)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-4297-1?
The severity of USN-4297-1 is moderate.
How does runC vulnerability in USN-4297-1 impact Ubuntu 18.04 LTS?
The runC vulnerability in USN-4297-1 could allow an attacker with a malicious container image to mount over the /proc directory and escalate privileges in Ubuntu 18.04 LTS.
How can I fix the runC vulnerability in USN-4297-1 on Ubuntu 18.04 LTS?
To fix the runC vulnerability in USN-4297-1 on Ubuntu 18.04 LTS, you need to update the `runc` package to version 1.0.0~rc10-0ubuntu1~18.04.2 or later.
Is Ubuntu 19.10 affected by the runC vulnerability in USN-4297-1?
No, Ubuntu 19.10 is not affected by the runC vulnerability in USN-4297-1.
Where can I find more information about the runC vulnerabilities in USN-4297-1?
You can find more information about the runC vulnerabilities in USN-4297-1 on the Ubuntu Security Notices page: [https://ubuntu.com/security/notices/USN-4297-1](https://ubuntu.com/security/notices/USN-4297-1)