Loading
util.c in runV 1.0.0 for Docker mishandles a numeric username, which allows attackers to obtain root access by leveraging the presence of an initial numeric value on an /etc/passwd line, and then issuing a "docker exec" command with that value in the -u argument, a similar issue to CVE-2016-3697.
Cite this page
CVE-2018-9862. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2018-9862
Use CWE-838, Hyper vendor hub and Runv product page to widen CVE-2018-9862 into its surrounding weakness, vendor, and product context.