This alert may not be shared outside your organization, Do Not Repost or send, place on other websites, List servers, or send to others via email, including other associations or parties.  Members and Law enforcement use only. Contact us for any permissions.  To do otherwise will result in the loss of membership.

Complete Story
 

02/13/2019

High Severity RunC Vulnerability Exposes Docker And Kubernetes Hosts

The State of Security

Often claimed as a worst-case scenario, a container breakout vulnerability has been discovered in RunC, the universal container runtime used by Docker, Kubernetes and other containerization systems.

Further research has discovered that a similar version of the same vulnerability affects the LXC and Apache Mesos packages. Identified as CVE-2019-5736, this vulnerability grants root access to host systems running all of the most popular containerization technologies.

A container breakout occurs when a malicious Docker image or container exploits a vulnerability in order to achieve a level of access on the host system. While extremely rare, it has been years since a container breakout vulnerability has been disclosed in a core component of Docker – that streak has now ended.

This vulnerability allows a container to overwrite the RunC binary and gain root level code execution access with minimal user interaction.  This vulnerability can be exploited in the following ways:

  • Creating a new container based on a malicious attacker controlled image
  • Attaching to an existing container which an attacker had previous write access to

Since a large portion of containers are based on images created by third-parties, it is vital to patch systems immediately as most users will have exposure to images and containers created by unknown parties.

Read more...

Printer-Friendly Version


Resources

Alerts

The FRPA alert system distinguishes us from other groups by gathering and providing information to law enforcement, retailers AND financial institutions.

more information
Resources

Resources

Your electronic library to help in fighting financial fraud for all of our partners.

more information