High severity7.5NVD Advisory· Published Sep 25, 2019· Updated Jun 17, 2026
CVE-2019-16884
CVE-2019-16884
Description
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/opencontainers/runcGo | < 1.0.0-rc8.0.20190930145003-cad42f6e0932 | 1.0.0-rc8.0.20190930145003-cad42f6e0932 |
github.com/opencontainers/selinuxGo | < 1.3.1-0.20190929122143-5215b1806f52 | 1.3.1-0.20190929122143-5215b1806f52 |
Affected products
68cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*range: >=0.0.1,<=0.1.1
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc5:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc6:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc7:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc8:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.2:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*
- runc/runcdescription
- osv-coords40 versionspkg:apk/chainguard/py3-dockerpkg:apk/chainguard/py3-supported-dockerpkg:apk/chainguard/py3.10-dockerpkg:apk/chainguard/py3.11-dockerpkg:apk/chainguard/py3.12-dockerpkg:apk/chainguard/py3.13-dockerpkg:apk/chainguard/runcpkg:apk/chainguard/runc-docpkg:apk/wolfi/py3-dockerpkg:apk/wolfi/py3-supported-dockerpkg:apk/wolfi/py3.10-dockerpkg:apk/wolfi/py3.11-dockerpkg:apk/wolfi/py3.12-dockerpkg:apk/wolfi/py3.13-dockerpkg:apk/wolfi/runcpkg:apk/wolfi/runc-docpkg:golang/github.com/opencontainers/runcpkg:golang/github.com/opencontainers/selinuxpkg:rpm/almalinux/oci-systemd-hookpkg:rpm/almalinux/oci-umountpkg:rpm/opensuse/containerd&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/docker&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/docker-runc&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/docker-runc&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/golang-github-docker-libnetwork&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/runc&distro=openSUSE%20Tumbleweedpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP1pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP1pkg:rpm/suse/docker-runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012pkg:rpm/suse/docker-runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015pkg:rpm/suse/docker-runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP1pkg:rpm/suse/golang-github-docker-libnetwork&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012pkg:rpm/suse/golang-github-docker-libnetwork&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015pkg:rpm/suse/golang-github-docker-libnetwork&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP1pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP1
< 0+ 39 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 1.0.0-rc8.0.20190930145003-cad42f6e0932
- (no CPE)range: < 1.3.1-0.20190929122143-5215b1806f52
- (no CPE)range: < 1:0.1.15-2.git2d0b8a3.module_el8.5.0+119+9a9ec082
- (no CPE)range: < 2:2.3.4-2.git87f9237.module_el8.5.0+119+9a9ec082
- (no CPE)range: < 1.2.10-lp151.2.9.1
- (no CPE)range: < 19.03.5_ce-lp151.2.15.1
- (no CPE)range: < 1.0.0rc8+gitr3826_425e105d5a03-lp150.5.28.1
- (no CPE)range: < 1.0.0rc8+gitr3826_425e105d5a03-lp151.3.9.1
- (no CPE)range: < 0.7.0.1+gitr2877_3eb39382bfa6-lp151.2.9.1
- (no CPE)range: < 1.0.2-1.2
- (no CPE)range: < 1.2.10-16.26.1
- (no CPE)range: < 1.2.10-5.19.1
- (no CPE)range: < 1.2.10-5.19.1
- (no CPE)range: < 19.03.5_ce-98.51.1
- (no CPE)range: < 19.03.5_ce-6.31.1
- (no CPE)range: < 19.03.5_ce-6.31.1
- (no CPE)range: < 1.0.0rc8+gitr3826_425e105d5a03-1.32.1
- (no CPE)range: < 1.0.0rc8+gitr3826_425e105d5a03-6.24.1
- (no CPE)range: < 1.0.0rc8+gitr3826_425e105d5a03-6.24.1
- (no CPE)range: < 0.7.0.1+gitr2877_3eb39382bfa6-28.1
- (no CPE)range: < 0.7.0.1+gitr2877_3eb39382bfa6-4.18.1
- (no CPE)range: < 0.7.0.1+gitr2877_3eb39382bfa6-4.18.1
- (no CPE)range: < 1.0.0~rc93-16.8.1
- (no CPE)range: < 1.0.0~rc8-1.6.1
Patches
Vulnerability mechanics
References
28- github.com/opencontainers/runc/issues/2128nvdExploitIssue TrackingThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2019-10/msg00073.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2019-11/msg00009.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2020-01/msg00010.htmlnvdMailing ListThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3940nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4074nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4269nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-fgv8-vj5c-2ppqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-16884ghsaADVISORY
- security.gentoo.org/glsa/202003-21nvdThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20220221-0004/nvdThird Party Advisory
- usn.ubuntu.com/4297-1/nvdThird Party Advisory
- github.com/crosbymichael/runc/commit/78dce1cf1ec36bbe7fe6767bdb81f7cbf6d34d70ghsaWEB
- github.com/opencontainers/runc/commit/cad42f6e0932db0ce08c3a3d9e89e6063ec283e4ghsaWEB
- github.com/opencontainers/runc/pull/2129ghsaWEB
- github.com/opencontainers/runc/pull/2130ghsaWEB
- github.com/opencontainers/selinux/commit/03b517dc4fd57245b1cf506e8ba7b817b6d309daghsaWEB
- lists.debian.org/debian-lts-announce/2023/02/msg00016.htmlnvdWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/62OQ2P7K5YDZ5BRCH2Q6DHUJIHQD3QCDghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/DGK6IV5JGVDXHOXEKJOJWKOVNZLT6MYRghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/SPK4JWP32BUIVDJ3YODZSOEVEW6BHQCFghsaWEB
- pkg.go.dev/vuln/GO-2021-0085ghsaWEB
- security.netapp.com/advisory/ntap-20220221-0004ghsaWEB
- usn.ubuntu.com/4297-1ghsaWEB
- lists.debian.org/debian-lts-announce/2023/03/msg00023.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62OQ2P7K5YDZ5BRCH2Q6DHUJIHQD3QCD/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DGK6IV5JGVDXHOXEKJOJWKOVNZLT6MYR/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPK4JWP32BUIVDJ3YODZSOEVEW6BHQCF/nvd
News mentions
0No linked articles in our index yet.