CVE-2018-10892: Docker

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

Affected products

  • Docker Docker: from 1.11, up to and including 18.03.1
  • Mobyproject Moby: from 1.11, up to and including 17.03.2
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Red Hat Enterprise Linux: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Openstack: version 12 only

Published 2018-07-06. Last modified 2026-06-17.