CVE-2019-16884: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 4.4% chance of exploitation in the next 30 days.
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 19.10 only
- Docker Docker: up to and including 19.03.2
- Fedoraproject Fedora: version 29 only; version 30 only; version 31 only
- Linuxfoundation Runc: from 0.0.1, up to and including 0.1.1; version 1.0.0 only
- Opensuse Leap: version 15.0 only; version 15.1 only
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only
- Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only
- Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only
- Red Hat Openshift Container Platform: version 4.1 only; version 4.2 only
Published 2019-09-25. Last modified 2026-06-17.