CVE-2018-20699

Public on 2019-01-12
Modified on 2021-12-02
Description
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
Severity
Low severity
Low
CVSS v3 Base Score
4.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Docker Extra docker 2021-10-22 ALAS2DOCKER-2021-003 Fixed
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra docker 2021-10-22 ALAS2NITRO-ENCLAVES-2021-003 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 4.5 CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv2 4.0 AV:N/AC:L/Au:S/C:N/I:N/A:P
NVD CVSSv3 4.9 CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H