Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/docker/docker(Go) | 0 | 1.6.1 | N/A |
CVSS Metrics