CVE-2019-14271

CRITICAL

Docker 19.03.x <19.03.1 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-14271. PoCs published by LouisLiuNova.

AI-analyzed exploit summary This repository provides a functional exploit for CVE-2019-14271, a Docker container breakout vulnerability. It includes scripts to set up the environment, build a vulnerable container, and execute the exploit to escape the container and access the host filesystem.

Description

In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.

Exploits (1)

nomisec WORKING POC 1 stars
by LouisLiuNova · poc
https://github.com/LouisLiuNova/CVE-2019-14271_Exploit

This repository provides a functional exploit for CVE-2019-14271, a Docker container breakout vulnerability. It includes scripts to set up the environment, build a vulnerable container, and execute the exploit to escape the container and access the host filesystem.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Docker (versions affected by CVE-2019-14271)
No auth needed
Prerequisites: Docker installed on the target system · Ability to run Docker containers
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory x_refsource_misc
https://github.com/moby/moby/issues/39449
Release Notes, Third Party Advisory x_refsource_confirm
https://docs.docker.com/engine/release-notes/
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190828-0003/
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2019/dsa-4521
Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Sep/21

Scores

CVSS v3 9.8
EPSS 0.7192
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-665
Status published
Products (5)
debian/debian_linux 10.0
docker/docker 19.03 - 19.03.1
docker/docker 19.03.0 - 19.03.1Go
opensuse/leap 15.0
opensuse/leap 15.1
Published Jul 29, 2019
Tracked Since Feb 18, 2026