• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

Docker contains an unpatched rare condition vulnerability

5656

A major security vulnerability has been found in Docker containers.

The Docker containers are said to be holding several major security vulnerabilities as a function in it called FollowSymlinkInScope can be exploited by attackers to modify resource paths.

This flaw was found out by a security researcher Aleksa Sarai who witnessed a Time-of-check to time-of-use (TOCTOU) attack because of the said function.

The vulnerability is yet to be patched from Docker's side, and it is to be noted that all the current docker versions contain this flaw.

FollowSymlinkInScope function was found incorrectly resolving resource paths in Docker container.

According to Sarai, an attacker adding a symbolic link after the faulty resolution can read and write access to the resource path, leading to a race condition.

There are two exploits scripts for this vulnerability which allows the modification of resource paths. “Attacked are two reproducers of the issue. They both include a Docker image which contains a simple binary that does a RENAME_EXCHANGE of a symlink to "/" and an empty directory in a loop, hoping to hit the race condition. In both of the scripts, the user is trying to copy a file to or from a path containing the swapped symlink,” Sarai stated.

Docker Inc is expected to release a patch for this flaw anytime soon.

Tags:
jayce
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 0 )

No questions available

Related Tutorials in Docker contains an unpatched rare condition vulnerability

Related Tutorials in Docker contains an unpatched rare condition vulnerability

How to Install Docker-CE on RHEL-7.6
How to Install Docker-CE on RHEL-7.6
Sep 11, 2020
How to Install Nagios Core by Docker on Ubuntu 21.04
How to Install Nagios Core by Docker on Ubuntu 21.04
Mar 10, 2022
How To Install Docker Compose on CentOS 7
How To Install Docker Compose on CentOS 7
Feb 15, 2018
How to Install and use Docker on CentOS-7.6
How to Install and use Docker on CentOS-7.6
Sep 2, 2020
How to Host Multiple Docker Containers with Nginx Reverse Proxy on Ubuntu 21.04
How to Host Multiple Docker Containers with Nginx Reverse Proxy on Ubuntu 21.04
Feb 15, 2022
How to Build a Lamp Stack Docker Container on Ubuntu 21.04
How to Build a Lamp Stack Docker Container on Ubuntu 21.04
Mar 8, 2022
How to Install Docker on Oracle Linux
How to Install Docker on Oracle Linux
Jan 3, 2022
How to install Docker and run images on Ubuntu 21.04
How to install Docker and run images on Ubuntu 21.04
Oct 26, 2021

Related News in Docker contains an unpatched rare condition vulnerability

Related News in Docker contains an unpatched rare condition vulnerability

Docker friendly Alpine Linux gets hardened Node.js
Docker friendly Alpine Linux gets hardened Node.js
Apr 19, 2017
CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
Mar 12, 2019
URL Attacks and The Ways to Stay Away from Them!
URL Attacks and The Ways to Stay Away from Them!
Mar 19, 2019
ATM Skimming Attack With Hijacked ATM Security Camera to Steal User’s PIN
ATM Skimming Attack With Hijacked ATM Security Camera to Steal User’s PIN
Mar 13, 2019
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Sep 7, 2019
Magecart Targets OpenCart Websites Payment Information
Magecart Targets OpenCart Websites Payment Information
May 17, 2019
WordPress 5.1.1 fixes a threatening XSS vulnerability
WordPress 5.1.1 fixes a threatening XSS vulnerability
Mar 22, 2019
Major Security Flaw Found in Cisco Routers
Major Security Flaw Found in Cisco Routers
Oct 2, 2019
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Ryan ?
how to use visual traceroute tool

Am using traceroute command to check for the route. i got this tool while surfing. So pls help me out installation and usage of Visual traceroute tool.

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.