CVE-2020-14300
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2016-9962, that was previously corrected in the docker packages in Red Hat Enterprise Linux 7 Extras via RHSA-2017:0116 (https://access.redhat.com/errata/RHSA-2017:0116). The CVE-2020-14300 was assigned to this security regression and it is specific to the docker packages produced by Red Hat. The original issue - CVE-2016-9962 - could possibly allow a process inside container to compromise a process entering container namespace and execute arbitrary code outside of the container. This could lead to compromise of the container host or other containers running on the same container host. This issue only affects a single version of Docker, 1.13.1-108.git4ef4b30, shipped in Red Hat Enterprise Linux 7. Both earlier and later versions are not affected.
EPSS 0.36% · 58.5th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Docker | * |
| redhat | enterprise_linux_server | 7.0 |
| docker | docker | 1.13.1 |
Timeline
- Jul 13, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 25, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 27, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://access.redhat.com/errata/RHBA-2020:0427 url
- https://access.redhat.com/security/cve/CVE-2016-9962 url
- https://access.redhat.com/security/vulnerabilities/cve-2016-9962 url
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9962 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-14300 advisory
- https://access.redhat.com/errata/RHSA-2020:2653 url
- https://access.redhat.com/security/cve/CVE-2020-14300 url
- https://access.redhat.com/security/vulnerabilities/runc-regression-docker-1.13.1-108 url
- https://bugzilla.redhat.com/show_bug.cgi?id=1848829 url