Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20190213090934.mnnitmk4onepvenu@mikami>
Date: Wed, 13 Feb 2019 20:09:34 +1100
From: Aleksa Sarai <asarai@...e.de>
To: Loganaden Velvindron <loganaden@...il.com>
Cc: oss-security@...ts.openwall.com, Solar Designer <solar@...nwall.com>,
	Aleksa Sarai <cyphar@...har.com>, dev@...ncontainers.org,
	Christian Brauner <christian.brauner@...ntu.com>
Subject: Re: CVE-2019-5736: runc container breakout (all
 versions)

On 2019-02-13, Loganaden Velvindron <loganaden@...il.com> wrote:
> I think that someone already posted a PoC on github, AFAIK.

Yes, there is a PoC that someone outside of the embargo posted on
GitHub (it is quite different to the one we have but it is using a
related issue which our patch also fixed). At this point I might as well
post the actual exploit code (given that the original vulnerability
authors have published a blog post that basically outlines the
exploit[1]).

[1]: https://blog.dragonsector.pl/2019/02/cve-2019-5736-escape-from-docker-and.html

-- 
Aleksa Sarai
Senior Software Engineer (Containers)
SUSE Linux GmbH
<https://www.cyphar.com/>

Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.