Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/docker/docker
  4. ›
  5. GMS-2023-3981

GMS-2023-3981: /sys/devices/virtual/powercap accessible by default to containers

October 30, 2023 (updated December 27, 2023)

Intel’s RAPL (Running Average Power Limit) feature, introduced by the Sandy Bridge microarchitecture, provides software insights into hardware energy consumption. To facilitate this, Intel introduced the powercap framework in Linux kernel 3.13, which reads values via relevant MSRs (model specific registers) and provides unprivileged userspace access via sysfs.

References

  • github.com/advisories/GHSA-jq35-85cj-fj4p
  • github.com/moby/moby/security/advisories/GHSA-jq35-85cj-fj4p

Code Behaviors & Features

Detect and mitigate GMS-2023-3981 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 20.10.27, all versions starting from 21.0.0 before 23.0.8, all versions starting from 24.0.0 before 24.0.7

Fixed versions

  • 23.0.8
  • 24.0.7
  • 20.10.27

Solution

Upgrade to versions 23.0.8, 24.0.7, 20.10.27 or above.

Source file

go/github.com/docker/docker/GMS-2023-3981.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:07 +0000.