CVE-2020-14298
Summary
| CVE | CVE-2020-14298 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-13 21:15:00 UTC |
| Updated | 2023-02-12 23:39:00 UTC |
| Description | The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and other containers running on the same host. This issue only affects docker version 1.13.1-108.git4ef4b30.el7, shipped in Red Hat Enterprise Linux 7 Extras. Both earlier and later versions are not affected. |
Risk And Classification
Problem Types: CWE-273
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Docker | Docker | 1.13.1 | All | All | All |
| Application | Docker | Docker | 1.13.1 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 7.0 | All | All | All |
| Application | Redhat | Openshift Container Platform | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1848239 – (CVE-2020-14298) CVE-2020-14298 docker: Security regression of CVE-2019-5736 due to inclusion of vulnerable runc | MISC | bugzilla.redhat.com | |
| Red Hat Customer Portal | CONFIRM | access.redhat.com | Vendor Advisory |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MISC | access.redhat.com | |
| Red Hat Customer Portal | CONFIRM | access.redhat.com | Vendor Advisory |
| 1664908 – (CVE-2019-5736) CVE-2019-5736 runc: Execution of malicious containers allows for container escape and access to host filesystem | CONFIRM | bugzilla.redhat.com | Issue Tracking, Patch, Vendor Advisory |
| Runc regression - docker-1.13.1-108 - CVE-2016-8867, CVE-2020-14298, and CVE-2020-14300 - Red Hat Customer Portal | MISC | access.redhat.com | |
| runc - Malicious container escape - CVE-2019-5736 - Red Hat Customer Portal | CONFIRM | access.redhat.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.