CVE-2016-9962: Docker

Medium severity, CVSS 6.4. EPSS: 0.4% chance of exploitation in the next 30 days.

RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.

Affected products

  • Docker Docker: from 1.11.0, before 1.12.6 (fixed in 1.12.6)

Published 2017-01-31. Last modified 2026-06-17.