Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Docker Extra | docker | 2021-10-22 22:40 | ALAS2DOCKER-2021-003 |
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | docker | 2021-10-22 22:38 | ALAS2NITRO-ENCLAVES-2021-003 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 4.5 | CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
NVD | CVSSv2 | 4.0 | AV:N/AC:L/Au:S/C:N/I:N/A:P |
NVD | CVSSv3 | 4.9 | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |