Docker is vulnerable to a symlink-race attack

Docker is vulnerable to a symlink-race attack

CVE-2018-15664: docker (all versions) is vulnerable to a symlink-race attack From: Aleksa Sarai

Date: Tue, 28 May 2019 14:25:13 +1000

There is no released Docker version with a fix for this issue at the time of writing. sh, I get a <1% chance of hitting the race condition (my attack script is quite dumb, it's possible with better timing you'd be able to hit the race window much more effectively). [1]: [2]: [3]: [4]: [5]: [6]: — Aleksa Sarai Senior Software Engineer (Containers) SUSE Linux GmbH CVE-2018-15664: docker (all versions) is vulnerable to a symlink-race attack Aleksa Sarai (May 27)

Source: seclists.org