Bug 1191015 (CVE-2021-41089) - VUL-0: CVE-2021-41089: docker: "cp" can chmod host files
Summary: VUL-0: CVE-2021-41089: docker: "cp" can chmod host files
Status: RESOLVED FIXED
Alias: CVE-2021-41089
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Containers Team
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/311121/
Whiteboard: CVSSv3.1:SUSE:CVE-2021-41089:3.6:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2021-09-28 07:17 UTC by Marcus Meissner
Modified: 2024-05-23 07:02 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 2 Marcus Meissner 2021-10-06 12:18:06 UTC
is public

https://vuldb.com/de/?id.183792

https://github.com/moby/moby/security/advisories/GHSA-v994-f8vw-g7j4


`docker cp` allows unexpected chmod of host files
low
thaJeztah published GHSA-v994-f8vw-g7j4 2 days ago
Package
No package listed
Affected versions
< 20.10.9
Patched versions
20.10.9
Description
Impact

A bug was found in Moby (Docker Engine) where attempting to copy files using docker cp into a specially-crafted container can result in Unix file permission changes for existing files in the host’s filesystem, widening access to others. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process.
Patches

This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers do not need to be restarted.
Workarounds

Ensure you only run trusted containers.
Credits

The Moby project would like to thank Lei Wang and Ruizhi Xiao for responsibly disclosing this issue in accordance with the Moby security policy.
For more information

If you have any questions or comments about this advisory:

    Open an issue
    Email us at  security@docker.com  if you think you’ve found a security bug
Comment 4 Aleksa Sarai 2021-10-07 11:42:07 UTC
Submitted this to SLES yesterday. I couldn't find the BZ for this issue so I just used the CVE number.
Comment 5 Swamp Workflow Management 2021-10-12 13:27:05 UTC
SUSE-SU-2021:3336-1: An update that solves 6 vulnerabilities and has three fixes is now available.

Category: security (important)
Bug References: 1102408,1185405,1187704,1188282,1191015,1191121,1191334,1191355,1191434
CVE References: CVE-2021-30465,CVE-2021-32760,CVE-2021-41089,CVE-2021-41091,CVE-2021-41092,CVE-2021-41103
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Containers 12 (src):    containerd-1.4.11-16.45.1, docker-20.10.9_ce-98.72.1, runc-1.0.2-16.14.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2021-10-25 13:17:47 UTC
openSUSE-SU-2021:3506-1: An update that solves 6 vulnerabilities and has four fixes is now available.

Category: security (important)
Bug References: 1102408,1185405,1187704,1188282,1190826,1191015,1191121,1191334,1191355,1191434
CVE References: CVE-2021-30465,CVE-2021-32760,CVE-2021-41089,CVE-2021-41091,CVE-2021-41092,CVE-2021-41103
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, docker-kubic-20.10.9_ce-156.1, runc-1.0.2-23.1
Comment 7 Swamp Workflow Management 2021-10-25 13:20:34 UTC
SUSE-SU-2021:3506-1: An update that solves 6 vulnerabilities and has four fixes is now available.

Category: security (important)
Bug References: 1102408,1185405,1187704,1188282,1190826,1191015,1191121,1191334,1191355,1191434
CVE References: CVE-2021-30465,CVE-2021-32760,CVE-2021-41089,CVE-2021-41091,CVE-2021-41092,CVE-2021-41103
JIRA References: 
Sources used:
SUSE MicroOS 5.1 (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE MicroOS 5.0 (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE Linux Enterprise Server for SAP 15 (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE Linux Enterprise Server 15-LTSS (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE Linux Enterprise Module for Containers 15-SP3 (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE Linux Enterprise Module for Containers 15-SP2 (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1
SUSE Enterprise Storage 7 (src):    runc-1.0.2-23.1
SUSE Enterprise Storage 6 (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1
SUSE CaaS Platform 4.0 (src):    containerd-1.4.11-56.1, docker-20.10.9_ce-156.1, runc-1.0.2-23.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2021-10-31 20:40:44 UTC
openSUSE-SU-2021:1404-1: An update that solves 6 vulnerabilities and has four fixes is now available.

Category: security (important)
Bug References: 1102408,1185405,1187704,1188282,1190826,1191015,1191121,1191334,1191355,1191434
CVE References: CVE-2021-30465,CVE-2021-32760,CVE-2021-41089,CVE-2021-41091,CVE-2021-41092,CVE-2021-41103
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    containerd-1.4.11-lp152.2.12.1, docker-20.10.9_ce-lp152.2.18.1, runc-1.0.2-lp152.2.9.1
Comment 12 Swamp Workflow Management 2022-01-27 17:20:12 UTC
SUSE-SU-2022:0213-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1191015,1191121,1191334,1191434,1193273
CVE References: CVE-2021-41089,CVE-2021-41091,CVE-2021-41092,CVE-2021-41103,CVE-2021-41190
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Containers 12 (src):    containerd-1.4.12-16.49.1, docker-20.10.12_ce-98.75.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2022-02-04 14:23:24 UTC
openSUSE-SU-2022:0334-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1191015,1191121,1191334,1191434,1193273
CVE References: CVE-2021-41089,CVE-2021-41091,CVE-2021-41092,CVE-2021-41103,CVE-2021-41190
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    containerd-1.4.12-60.1, docker-20.10.12_ce-159.1, docker-kubic-20.10.12_ce-159.1
Comment 14 Swamp Workflow Management 2022-02-04 14:26:08 UTC
SUSE-SU-2022:0334-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1191015,1191121,1191334,1191434,1193273
CVE References: CVE-2021-41089,CVE-2021-41091,CVE-2021-41092,CVE-2021-41103,CVE-2021-41190
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Containers 15-SP3 (src):    containerd-1.4.12-60.1, docker-20.10.12_ce-159.1
SUSE Linux Enterprise Micro 5.1 (src):    containerd-1.4.12-60.1, docker-20.10.12_ce-159.1
SUSE Linux Enterprise Micro 5.0 (src):    containerd-1.4.12-60.1, docker-20.10.12_ce-159.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 15 Aleksa Sarai 2024-05-23 07:02:22 UTC
Fixed in 2021.