A flaw was found in the `userns-remap` feature of Docker. The root user in the remapped namespace can modify files under /var/lib/docker/<remapping>, leading to possible privilege escalation to the root user in the host. The highest threat from this vulnerability is to data integrity.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 1 | docker | 2021-11-11 20:21 | ALAS-2021-1550 |
Amazon Linux 2 - Docker Extra | docker | 2021-10-19 18:50 | ALAS2DOCKER-2021-001 |
Amazon Linux 2 - Ecs Extra | docker | 2023-10-18 22:01 | ALAS2ECS-2023-015 |
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | docker | 2021-10-19 18:51 | ALAS2NITRO-ENCLAVES-2021-001 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 6.0 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N |
NVD | CVSSv2 | 2.7 | AV:A/AC:L/Au:S/C:N/I:P/A:N |
NVD | CVSSv3 | 6.8 | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N |