CVE-2016-9962: Docker
Medium severity, CVSS 6.4. EPSS: 0.4% chance of exploitation in the next 30 days.
RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.
Affected products
- Docker Docker: from 1.11.0, before 1.12.6 (fixed in 1.12.6)
Published 2017-01-31. Last modified 2026-06-17.