Process Isolation Flaw in rkt Container Runtime by CoreOS
CVE-2019-10145

7HIGH

Key Information:

Vendor

[unknown]

Status
Vendor
CVE Published:
3 June 2019

What is CVE-2019-10145?

A flaw in rkt container runtime allows processes initiated with 'rkt enter' to bypass security mechanisms, enabling them to access host resources. This vulnerability arises due to insufficient process isolation and lack of seccomp filtering in the container environment during stage 2 execution. Attackers exploiting this vulnerability could potentially access sensitive data and control host operations. It is crucial for users of rkt versions up to 1.30.0 to apply necessary updates to mitigate the risk.

Affected Version(s)

rkt 1.30.0

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.