CVE-2018-20699
Public on 2019-01-12
Modified on 2021-12-02
Description
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 2 - Docker Extra | docker | 2021-10-22 | ALAS2DOCKER-2021-003 | Fixed |
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | docker | 2021-10-22 | ALAS2NITRO-ENCLAVES-2021-003 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 4.5 | CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
NVD | CVSSv2 | 4.0 | AV:N/AC:L/Au:S/C:N/I:N/A:P |
NVD | CVSSv3 | 4.9 | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |