CVE-2019-5736: Apache Mesos
High severity, CVSS 8.6. EPSS: 98.5% chance of exploitation in the next 30 days.
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
Affected products
- Apache Mesos: from 1.4.0, before 1.4.3 (fixed in 1.4.3); from 1.5.0, before 1.5.3 (fixed in 1.5.3); from 1.6.0, before 1.6.2 (fixed in 1.6.2); from 1.7.0, before 1.7.2 (fixed in 1.7.2)
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 18.10 only; version 19.04 only
- d2iq Dc/os: before 1.10.10 (fixed in 1.10.10); from 1.10.11, before 1.11.9 (fixed in 1.11.9); from 1.11.10, before 1.12.1 (fixed in 1.12.1)
- d2iq Kubernetes Engine: before 2.2.0-1.13.3 (fixed in 2.2.0-1.13.3)
- Docker Docker: before 18.09.2 (fixed in 18.09.2)
- Fedoraproject Fedora: version 29 only; version 30 only
- Google Kubernetes Engine: affected versions not specified
- HP Onesphere: affected versions not specified
- Linuxcontainers Lxc: before 3.2.0 (fixed in 3.2.0)
- Linuxfoundation Runc: up to and including 0.1.1; version 1.0.0 only
- Micro Focus Service Management Automation: version 2018.02 only; version 2018.05 only; version 2018.08 only; version 2018.11 only
- Netapp Hci Management Node: affected versions not specified
- Netapp Solidfire: affected versions not specified
- Opensuse Backports Sle: version 15.0 only
- Opensuse Leap: version 15.0 only; version 15.1 only; version 42.3 only
- Red Hat Container Development Kit: version 3.7 only
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Openshift: version 3.4 only; version 3.5 only; version 3.6 only; version 3.7 only
Published 2019-02-11. Last modified 2026-06-17.