DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2015-3627

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2015-3627

CGA ID

CGA-524r-9jqj-x2rv

Description

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images