CVE-2019-0204
Description
A specially crafted Docker image can overwrite the init helper binary in Apache Mesos, leading to root-level code execution on the host.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A specially crafted Docker image can overwrite the init helper binary in Apache Mesos, leading to root-level code execution on the host.
Vulnerability
A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos. Affected versions include all versions before 1.4.x, 1.4.0 through 1.4.2, 1.5.0 through 1.5.2, 1.6.0 through 1.6.1, and 1.7.0 through 1.7.1 [1][2].
Exploitation
An attacker must be able to run a Docker image as the root user within a Mesos task. By crafting a malicious Docker image that overwrites the init helper binary or command executor, the attacker can execute arbitrary code when the container runtime initializes or executes commands [2].
Impact
Successful exploitation allows the attacker to gain root-level code execution on the host system, leading to full compromise of the host [1][2].
Mitigation
Red Hat published an advisory (RHSA-2019:3892) with a fix for affected Red Hat products. For Apache Mesos, the vulnerability is fixed in versions 1.4.3, 1.5.3, 1.6.2, and 1.7.2. Users should upgrade to these or later versions [1].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.mesos:mesosMaven | < 1.4.3 | 1.4.3 |
org.apache.mesos:mesosMaven | >= 1.5.0, < 1.5.3 | 1.5.3 |
org.apache.mesos:mesosMaven | >= 1.6.0, < 1.6.2 | 1.6.2 |
org.apache.mesos:mesosMaven | >= 1.7.0, < 1.7.2 | 1.7.2 |
Affected products
2- Apache/Apache Mesosv5Range: pre-1.4.x
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- access.redhat.com/errata/RHSA-2019:3892ghsavendor-advisoryx_refsource_REDHATWEB
- github.com/advisories/GHSA-32w9-2qpc-5f9vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-0204ghsaADVISORY
- www.securityfocus.com/bid/107605ghsavdb-entryx_refsource_BIDWEB
- lists.apache.org/thread.html/b162dd624dc088cd634292f0402282a1d1d0ce853baeae8205bc033c%40%3Cdev.mesos.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/b162dd624dc088cd634292f0402282a1d1d0ce853baeae8205bc033c@%3Cdev.mesos.apache.org%3EghsaWEB
News mentions
0No linked articles in our index yet.