Red Hat Security Advisory 2015-0623-02

Red Hat Security Advisory 2015-0623-02 – Docker is a service providing container management on Linux. It was found that a malicious container image could overwrite arbitrary portions of the host file system by including absolute symlinks, potentially leading to privilege escalation. A flaw was found in the way the Docker service unpacked images or builds after a “docker pull”. An attacker could use this flaw to provide a malicious image or build that, when unpacked, would escalate their privileges on the system.

Leave a Reply