Vulnerability record · CVE-2018-20699 · published 12 January 2019
CVE-2018-20699: Docker engine uncontrolled resource consumption vulnerability
Docker · Engine
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
Description
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2019:0487 | Third Party Advisory |
| https://github.com/docker/engine/pull/70 | PatchThird Party Advisory |
| https://github.com/moby/moby/pull/37967 | PatchThird Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0487 | Third Party Advisory |
| https://github.com/docker/engine/pull/70 | PatchThird Party Advisory |
| https://github.com/moby/moby/pull/37967 | PatchThird Party Advisory |
Track CVE-2018-20699 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-20699), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.