Vulnerability Name:

CVE-2017-16539 (CCN-134489)

Assigned:2017-11-03
Published:2017-11-03
Updated:2017-11-27
Summary:The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.
CVSS v3 Severity:5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-200
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2017-16539

Source: XF
Type: UNKNOWN
docker-moby-cve201716539-dos(134489)

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://github.com/moby/moby/pull/35399

Source: CCN
Type: Moby GIT Repository
Add /proc/scsi to masked paths #35399

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://github.com/moby/moby/pull/35399/commits/a21ecdf3c8a343a7c94e4c4d01b178c87ca7aaa1

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://marc.info/?l=linux-scsi&m=150985062200941&w=2

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://marc.info/?l=linux-scsi&m=150985455801444&w=2

Source: MISC
Type: Third Party Advisory
https://twitter.com/ewindisch/status/926443521820774401

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mobyproject:moby:*:*:*:*:*:*:*:* (Version <= 17.03.2)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201716539
    V
    CVE-2017-16539
    2023-06-22
    oval:org.opensuse.security:def:7853
    P
    docker-20.10.23_ce-150000.175.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:604
    P
    Security update for virt-v2v (Moderate) (in QA)
    2022-09-05
    oval:org.opensuse.security:def:602
    P
    Security update for mariadb (Important)
    2022-07-27
    oval:org.opensuse.security:def:3243
    P
    libpython3_6m1_0-3.6.8-2.13 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94873
    P
    docker-20.10.12_ce-159.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:933
    P
    Security update for python-PyJWT (Important) (in QA)
    2022-06-21
    oval:org.opensuse.security:def:931
    P
    Security update for apache2 (Important) (in QA)
    2022-06-14
    oval:org.opensuse.security:def:939
    P
    Security update for wireshark (Moderate)
    2022-02-14
    oval:org.opensuse.security:def:112164
    P
    docker-20.10.6_ce-2.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:70024
    P
    Security update for go1.17 (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:100701
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:1295
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Important)
    2021-12-15
    oval:org.opensuse.security:def:1287
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:93988
    P
    (Important)
    2021-12-01
    oval:org.opensuse.security:def:1281
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:1279
    P
    Security update for the Linux Kernel (Live Patch 6 for SLE 15 SP3) (Important)
    2021-11-17
    oval:org.opensuse.security:def:105698
    P
    docker-20.10.6_ce-2.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:71202
    P
    grub2-2.02-24.12 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:69919
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:48040
    P
    gzip-1.10-2.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47125
    P
    perl-LWP-Protocol-https-6.04-5.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48280
    P
    python-cryptography-1.3.1-7.13.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47452
    P
    openssh-7.2p2-69.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14070
    P
    yast2-3.1.206-36.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48122
    P
    libhivex0-1.3.10-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47126
    P
    perl-Tk-804.031-3.76 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14001
    P
    pcsc-ccid-1.4.14-1.42 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47678
    P
    libXi6-1.7.4-17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48184
    P
    libqt4-32bit-4.8.7-8.8.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47138
    P
    python-pyOpenSSL-16.0.0-2.3.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47824
    P
    mailman-2.1.17-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13889
    P
    libasan2-32bit-5.3.1+r233831-9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48282
    P
    python-doc-2.7.13-28.31.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47454
    P
    openvswitch-2.7.0-2.29 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48124
    P
    libical1-1.0.1-16.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48351
    P
    xscreensaver-5.22-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47584
    P
    cups-1.7.5-20.17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14081
    P
    apache-commons-daemon-1.0.15-6.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13825
    P
    gdk-pixbuf-lang-2.34.0-16.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48186
    P
    libraptor2-0-2.0.10-3.63 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47140
    P
    python-requests-2.8.1-6.11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14026
    P
    rpm-32bit-4.11.2-15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47826
    P
    mariadb-10.2.18-1.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48249
    P
    openssh-7.2p2-74.45.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47259
    P
    gd-2.1.0-23.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48038
    P
    gv-3.7.4-1.36 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47123
    P
    perl-Config-IniFiles-2.82-3.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13908
    P
    libhogweed2-2.7.1-9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48353
    P
    yast2-core-3.3.1-1.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47586
    P
    cups-pk-helper-0.2.5-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14754
    P
    radvd-1.9.7-2.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47124
    P
    perl-HTML-Parser-3.71-1.145 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14732
    P
    perl-LWP-Protocol-https-6.04-5.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47676
    P
    libXfont1-1.5.1-11.3.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14094
    P
    bash-4.3-82.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13872
    P
    libXfixes3-32bit-5.0.1-3.53 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48251
    P
    opie-2.4-724.56 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47261
    P
    gdk-pixbuf-loader-rsvg-2.40.15-4.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:62384
    P
    docker-19.03.15_ce-6.46.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101128
    P
    docker-19.03.15_ce-6.46.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:38125
    P
    Security update for djvulibre (Important)
    2021-08-04
    oval:org.opensuse.security:def:13757
    P
    xorg-x11-server-7.6_1.15.2-36.21 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71089
    P
    python2-salt-2018.3.0-3.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13727
    P
    squidGuard-1.4-23.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13735
    P
    tar-1.27.1-4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:55202
    P
    Security update for spice (Important)
    2021-06-08
    oval:org.opensuse.security:def:56025
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:64502
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:55179
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:55180
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:67749
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15) (Important)
    2021-04-07
    oval:org.opensuse.security:def:55859
    P
    Security update for the Linux Kernel (Important)
    2021-03-09
    oval:org.opensuse.security:def:38434
    P
    Security update for salt (Critical)
    2021-02-26
    oval:org.opensuse.security:def:62376
    P
    docker-19.03.5_ce-6.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107367
    P
    docker-19.03.5_ce-6.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116925
    P
    docker-19.03.5_ce-6.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62368
    P
    docker-17.09.1_ce-4.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:89846
    P
    docker-18.09.1_ce-6.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62370
    P
    docker-18.09.1_ce-6.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103501
    P
    docker-18.09.1_ce-6.14.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:37746
    P
    bzip2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39232
    P
    shotwell on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38215
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56703
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55753
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39274
    P
    Version update for docker, docker-runc, containerd, golang-github-docker-libnetwork (Important)
    2020-12-01
    oval:org.opensuse.security:def:64415
    P
    logrotate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38594
    P
    freeradius-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38068
    P
    squidGuard on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56584
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55342
    P
    pam_krb5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56310
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:49318
    P
    python3-salt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38522
    P
    xlockmore on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49372
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37830
    P
    kbd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66576
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38375
    P
    libsrtp1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37734
    P
    at on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66668
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73359
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49320
    P
    python3-urllib3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37735
    P
    audiofile on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73241
    P
    libvorbis-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56622
    P
    Security update for binutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55580
    P
    Security update for zeromq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49374
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56418
    P
    Security update for perl-XML-LibXML (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38550
    P
    autofs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67849
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37967
    P
    libssh4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56510
    P
    Security update for xdg-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49326
    P
    rsyslog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49380
    P
    docker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38483
    P
    socat on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:2017165390000000
    V
    CVE-2017-16539 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-11-04
    oval:com.ubuntu.artful:def:201716539000
    V
    CVE-2017-16539 on Ubuntu 17.10 (artful) - medium.
    2017-11-04
    oval:com.ubuntu.xenial:def:201716539000
    V
    CVE-2017-16539 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-11-04
    oval:com.ubuntu.xenial:def:2017165390000000
    V
    CVE-2017-16539 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-11-04
    oval:com.ubuntu.bionic:def:201716539000
    V
    CVE-2017-16539 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-11-04
    oval:com.ubuntu.cosmic:def:201716539000
    V
    CVE-2017-16539 on Ubuntu 18.10 (cosmic) - medium.
    2017-11-04
    oval:com.ubuntu.cosmic:def:2017165390000000
    V
    CVE-2017-16539 on Ubuntu 18.10 (cosmic) - medium.
    2017-11-04
    oval:com.ubuntu.trusty:def:201716539000
    V
    CVE-2017-16539 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-11-04
    BACK
    mobyproject moby *