{"schema_version":"1.9.0","id":"CVE-2019-14271","published":"2019-07-29T18:15:11.223Z","modified":"2026-08-27T03:48:23.287286904Z","aliases":["GHSA-v2cv-wwxq-qq97","GO-2024-2521"],"related":["SUSE-SU-2019:2117-1","SUSE-SU-2019:2119-1","SUSE-SU-2025:03540-1","SUSE-SU-2025:03545-1","openSUSE-SU-2019:2021-1","openSUSE-SU-2024:10722-1","openSUSE-SU-2025:15589-1"],"details":"In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/docker-archive/docker-ce","events":[{"introduced":"aeac9490dc54c1d48b3d7ae9a46f5a19b78dcd3a"},{"fixed":"74b1e89e8ac68948be88fe0aa1e2767ae28659fe"}],"database_specific":{"cpe":"cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"19.03"},{"fixed":"19.03.1"}],"source":"CPE_RANGE"}}],"versions":["v19.03.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14271.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/docker-archive/engine","events":[{"introduced":"705d9623b7c1fac1f8cf48074d5861847d09eb67"},{"fixed":"fa8dd90ceb7bcb9d554d27e0b9087ab83e54bd2b"}],"database_specific":{"cpe":"cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"19.03"},{"fixed":"19.03.1"}],"source":"CPE_RANGE"}}],"versions":["v19.03.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14271.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/moby/moby","events":[{"introduced":"705d9623b7c1fac1f8cf48074d5861847d09eb67"},{"fixed":"fa8dd90ceb7bcb9d554d27e0b9087ab83e54bd2b"}],"database_specific":{"cpe":"cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"19.03"},{"fixed":"19.03.1"}],"source":"CPE_RANGE"}}],"versions":["v19.03.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14271.json"}}],"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html"},{"type":"ADVISORY","url":"https://docs.docker.com/engine/release-notes/"},{"type":"ADVISORY","url":"https://github.com/moby/moby/issues/39449"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Sep/21"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20190828-0003/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4521"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"10.0"},{"last_affected":"10.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"cpes":["cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*","cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"15.0"},{"last_affected":"15.0"},{"introduced":"15.1"},{"last_affected":"15.1"}],"source":"CPE_STRING","vendor_product":"opensuse:leap"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}