CVE-2019-5736 affecting docker-ce 18.03

Bug #1815641 reported by Bruce Jones
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
StarlingX
Fix Released
Medium
Brent Rowsell

Bug Description

Erich (<email address hidden>) reported the following:

> - The CVE-2019-5736[0] affects runc which is used by docker another systems.
> - Currently StarlingX ship an affected version of docker-ce[1]
> - There's a new release of docker-ce with a patch[2] and there's an rpm available[3].
> - It's not clear yet what other systems might be affected by this vulnerability and if we ship it in starlingx.
>
> Erich
>
> [0] https://nvd.nist.gov/vuln/detail/CVE-2019-5736
> [1]
> https://github.com/openstack/stx-tools/blob/master/centos-mirror-tools
> /rpms_centos3rdparties.lst#L19 [2]
> https://github.com/docker/docker-ce/releases/tag/v18.09.2
> [3]
> https://download.docker.com/linux/centos/7/source/stable/Packages/dock
> er-ce-18.09.2-3.el7.src.rpm

On Feb 11, 2019, at 8:18 PM, Rowsell, Brent <email address hidden> wrote:
>
> We are running the affected version. There is no NIST score so until
> that is available, we have to see if this meets our CVE criteria Note our k8s version has not been validated upstream with docker-ce 18.09 so we can’t blindly update to it.

Ken Young replied:
> A couple of other points based on RHEL:
> 1/ This required local access and has high complexity. This is unlikely to match big criteria.
> 2/ there is no upstream fix at the moment

Cindy Xie replied:
> I agree on the assessment, but I think it will be necessary that we create a security bug to track this issue. Once the CVE NIST score and upstream fix available, we can make sure we upgrade the package in StarlingX.

CVE References

Ken Young (kenyis)
tags: added: stx.security
Revision history for this message
Ken Young (kenyis) wrote :

https://nvd.nist.gov/vuln/detail/CVE-2019-5736

Base Score: 9.3 HIGH
Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C) (V2 legend)

Note that this does not match patch-back criteria...

/KenY

Revision history for this message
Ken Young (kenyis) wrote :

Reciewed on Mar 25th with the security team. This needs to be corrected as part of a rebase. Assigning to Brent to see if we are getting this as part of the next docker rebase.

Changed in starlingx:
status: New → Triaged
importance: Undecided → Medium
assignee: nobody → Ken Young (kenyis)
assignee: Ken Young (kenyis) → Brent Rowsell (brent-rowsell)
Revision history for this message
Brent Rowsell (brent-rowsell) wrote :

StarlingX is now using docker-ce 18.09.6

Changed in starlingx:
status: Triaged → Fix Released
Ken Young (kenyis)
information type: Private Security → Public
Ghada Khalil (gkhalil)
tags: added: stx.2.0
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.