ALAS-2018-1071


Amazon Linux AMI Security Advisory: ALAS-2018-1071
Advisory Release Date: 2018-09-06 22:00 Pacific
Severity: Medium
References: CVE-2018-10892 

Issue Overview:

The default OCI Linux spec in oci/defaults{_linux}.go in Docker/Moby, from 1.11 to current, does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling Bluetooth or turning up/down keyboard brightness.(CVE-2018-10892 )


Affected Packages:

docker


Issue Correction:
Run yum update docker to update your system.

New Packages:
src:
    docker-18.06.1ce-2.16.amzn1.src

x86_64:
    docker-18.06.1ce-2.16.amzn1.x86_64
    docker-debuginfo-18.06.1ce-2.16.amzn1.x86_64