Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 7: 2020-0279 Moderate: Docker IPv6 Spoofing Risk

mageia
Calendar Grey July 5, 2020
Dist Mageia Esm H88
Recent updates to Docker packages address a significant IPv6 security flaw affecting Mageia 7. Discover the details of the resolution and the advisory issued.
Updated docker packages fix security vulnerability: A flaw was found in Docker when it creates network bridges that accept IPv6 router advertisements by default

Summary

Updated docker packages fix security vulnerability:
A flaw was found in Docker when it creates network bridges that accept IPv6 router advertisements by default. This flaw allows an attacker who can execute code in a container to possibly spoof rogue IPv6 router advertisements to perform a man-in-the-middle (MitM) attack against the host network or another container (CVE-2020-13401).

References

- https://bugs.mageia.org/show_bug.cgi?id=26815

- https://bugzilla.redhat.com/show_bug.cgi?id=1833233

- https://www.cve.org/CVERecord?id=CVE-2020-13401

Resolution

SRPMS

- 7/core/docker-18.09.9-1.1.mga7

Publication date: 05 Jul 2020
URL: https://advisories.mageia.org/MGASA-2020-0279.html
Type: security
CVE: CVE-2020-13401

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here