Amazon Linux 1 Security Advisory: ALAS-2018-1071
Advisory Release Date: 2018-09-05 19:30 Pacific
Advisory Updated Date: 2018-09-06 22:00 Pacific
The default OCI Linux spec in oci/defaults{_linux}.go in Docker/Moby, from 1.11 to current, does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling Bluetooth or turning up/down keyboard brightness.(CVE-2018-10892)
Affected Packages:
docker
Issue Correction:
Run yum update docker to update your system.
src:
docker-18.06.1ce-2.16.amzn1.src
x86_64:
docker-18.06.1ce-2.16.amzn1.x86_64
docker-debuginfo-18.06.1ce-2.16.amzn1.x86_64