CVE-2016-9962 describes a vulnerability in RunC, affecting Docker, where the container's pid 1 process could ptrace additional processes launched via 'runc exec'. This allowed a root-level main container process to access file descriptors of new processes during initialization, potentially leading to container escapes or manipulation of RunC's state. Rated Medium (CVSS 6.4), exploitation requires high privileges and high attack complexity, but could result in significant impact across confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or KEV listing, though it garnered some community discussion and media coverage at the time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.11.0, < 1.12.6CPE matchmatch criteria | cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.