• CVE-2018-10892

发布时间: 2022年7月30日

修改时间: 2022年7月30日

概要

The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host s hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.

CVSS v3 指标

NVD openEuler
CVSS评分 5.3 5.3
Attack Vector Network Network
Attack Complexity Low Low
Privileges Required None None
User Interaction None None
Scope Unchanged Unchanged
Confidentiality None None
Integrity Low Low
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2022-1690 The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host s hardware like enabling/disabling bluetooth or turning up/down keyboard brightness. 2022年7月30日

影响产品

产品 状态
KY3.4-4A docker Unaffected
KY3.4-5 docker Unaffected
KY3.5.1 docker Unaffected