CVE-2018-10892: Docker
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.
Affected products
- Docker Docker: from 1.11, up to and including 18.03.1
- Mobyproject Moby: from 1.11, up to and including 17.03.2
- Opensuse Leap: version 15.0 only; version 15.1 only
- Red Hat Enterprise Linux: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Openstack: version 12 only
Published 2018-07-06. Last modified 2026-06-17.