Description
The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.
Published: 2017-11-04
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-7732 The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.
Github GHSA Github GHSA GHSA-vfjc-2qcw-j95j Docker Moby /proc/scsi Path Exposure Allows Host Data Loss (SCSI MICDROP)
History

Tue, 27 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Mobyproject Moby
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-27T20:39:44.986Z

Reserved: 2017-11-04T00:00:00.000Z

Link: CVE-2017-16539

cve-icon Vulnrichment

Updated: 2024-08-05T20:27:03.794Z

cve-icon NVD

Status : Modified

Published: 2017-11-04T17:29:00.207

Modified: 2026-05-13T00:24:29.033

Link: CVE-2017-16539

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-11-03T00:00:00Z

Links: CVE-2017-16539 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses