Database/Container, Kubernetes & orchestration
Docker / moby: Default OCI spec does not mask /proc/acpi, so a container can change host hardware state
CVSS 5.3CVE-2018-10892Container, Kubernetes & orchestrationcurated
Impact
Default OCI spec does not mask /proc/acpi, so a container can change host hardware state
Who can reach it
Any tenant workload
What to do
Upgrade Docker Engine or add explicit maskedPaths
References
Related entries
- Docker / moby: Supplementary groups not set up properlyCVE-2022-36109 · Docker / mobyMedium
- Docker / moby: On firewalld reload, published container ports become reachable from outside despite the intendedCVE-2025-54388 · Docker / mobyMedium
- Docker / moby: IPv6 not disabled on interfaces where it should beCVE-2024-32473 · Docker / mobyMedium
- Docker / moby: Related firewalld handling defect affecting Moby port exposureCVE-2025-54410 · Docker / mobyLow
- Docker / moby: `docker cp` into a crafted container changes Unix permissions of existing host filesCVE-2021-41089 · Docker / mobyLow
- Docker / moby: Code injection into `docker cp` via nsswitch loading a library from the container chrootCVE-2019-14271 · Docker / mobyCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.