5.3
CVSSv3

CVE-2018-10892

Published: 06/07/2018 Updated: 12/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 447
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an malicious user to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

docker docker

mobyproject moby

redhat enterprise linux 7.0

redhat enterprise linux server 7.0

redhat openstack 12

opensuse leap 15.0

opensuse leap 15.1

Vendor Advisories

Debian Bug report logs - #908057 dockerio: CVE-2018-10892 Package: dockerio; Maintainer for dockerio is Dmitry Smirnov <onlyjob@debianorg>; Source for dockerio is src:dockerio (PTS, buildd, popcon) Reported by: Antoine Beaupre <anarcat@orangeseedsorg> Date: Wed, 5 Sep 2018 14:36:09 UTC Severity: grave Tags: ...
Synopsis Moderate: Red Hat Enterprise Linux OpenStack Platform security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenStack Platform 120 (Pike)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability ...
Synopsis Moderate: docker security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for docker is now available for Red Hat Enterprise Linux 7 ExtrasRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVS ...
The default OCI Linux spec in oci/defaults{_linux}go in Docker/Moby, from 111 to current, does not block /proc/acpi pathnames The flaw allows an attacker to modify host's hardware like enabling/disabling Bluetooth or turning up/down keyboard brightness(CVE-2018-10892) ...
The default OCI Linux spec in oci/defaults{_linux}go in Docker/Moby, from 111 to current, does not block /proc/acpi pathnames The flaw allows an attacker to modify host's hardware like enabling/disabling Bluetooth or turning up/down keyboard brightness (CVE-2018-10892) ...
The default OCI Linux spec in oci/defaults{_linux}go in Docker/Moby, from 111 to current, does not block /proc/acpi pathnames The flaw allows an attacker to modify host's hardware like enabling/disabling Bluetooth or turning up/down keyboard brightness (CVE-2018-10892) ...
The default OCI Linux spec in oci/defaults{_linux}go in Docker/Moby, from 111 to current, does not block /proc/acpi pathnames The flaw allows an attacker to modify host's hardware like enabling/disabling Bluetooth or turning up/down keyboard brightness ...
Description of Problem A number of security vulnerabilities have been identified in Citrix XenServer that may allow malicious code running in a PV guest VM to compromise the host and malicious privileged code running in an HVM guest VM to crash the host These vulnerabilities affect all currently supported versions of Citrix XenServer up to and inc ...