QID 375593
Date Published: 2021-05-31
QID 375593: Docker Engine Denial Of Service Vulnerability
Docker Engine enables containerized applications to run anywhere consistently on any infrastructure.
CVE-2020-27534 - util/binfmt_misc/check.go in Builder in Docker Engine calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call.
Affected Versions:
Docker Engine before 19.03.9
QID Detection Logic:
Vulnerable versions of docker are detected by running the Docker Engine --version command.
Successful exploitation can cause docker to crash.
Solution
Customers are advised to upgrade to Docker Engine 19.03.9 or later versions to remediate this vulnerability.
Vendor References
- CVE-2020-27534 -
docs.docker.com/engine/release-notes/19.03/#19039
CVEs related to QID 375593
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2020-27534 |
|