VDB
Sign up
MEDIUM

GHSA-g7v2-2qxx-wjrw

Symlink Attack in Libcontainer and Docker Engine

Quick fix

GHSA-g7v2-2qxx-wjrw — github.com/docker/docker: upgrade to the fixed version with the command below.

go get github.com/docker/docker@v1.6.1

Details

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/docker/docker
Introduced in: 0Fixed in: 1.6.1
Fixgo get github.com/docker/docker@v1.6.1

References