ALAS2NITRO-ENCLAVES-2021-005

Related Vulnerabilities: CVE-2018-10892  

The default OCI Linux spec in oci/defaults{_linux}.go in Docker/Moby, from 1.11 to current, does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling Bluetooth or turning up/down keyboard brightness. (CVE-2018-10892)

ALAS2NITRO-ENCLAVES-2021-005


Amazon Linux 2 Security Advisory: ALASNITRO-ENCLAVES-2021-005
Advisory Release Date: 2021-11-09 18:24 Pacific
Advisory Updated Date: 2021-11-18 21:37 Pacific
Severity: Medium
References: CVE-2018-10892 

Issue Overview:

The default OCI Linux spec in oci/defaults{_linux}.go in Docker/Moby, from 1.11 to current, does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling Bluetooth or turning up/down keyboard brightness. (CVE-2018-10892)


Affected Packages:

docker


Issue Correction:
Run yum update docker to update your system.

New Packages:
src:
    docker-18.06.1ce-2.amzn2.src

x86_64:
    docker-18.06.1ce-2.amzn2.x86_64
    docker-debuginfo-18.06.1ce-2.amzn2.x86_64