CVE-2019-14271: Debian Linux

Critical severity, CVSS 9.8. EPSS: 18.8% chance of exploitation in the next 30 days.

In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Docker Docker: from 19.03, before 19.03.1 (fixed in 19.03.1)
  • Opensuse Leap: version 15.0 only; version 15.1 only

Published 2019-07-29. Last modified 2026-06-17.