Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:0328-1

Опубликовано: 05 фев. 2024
Источник: suse-cvrf

Описание

Security update for runc

This update for runc fixes the following issues:

  • Update to runc v1.1.12 (bsc#1218894)

The following CVE was already fixed with the previous release.

  • CVE-2024-21626: Fixed container breakout.

Список пакетов

Image SLES12-SP5-Azure-Basic-On-Demand
runc-1.1.12-16.46.1
Image SLES12-SP5-Azure-Standard-On-Demand
runc-1.1.12-16.46.1
Image SLES12-SP5-EC2-ECS-On-Demand
runc-1.1.12-16.46.1
Image SLES12-SP5-EC2-On-Demand
runc-1.1.12-16.46.1
Image SLES12-SP5-GCE-On-Demand
runc-1.1.12-16.46.1
SUSE Linux Enterprise Module for Containers 12
runc-1.1.12-16.46.1

Описание

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.


Затронутые продукты
Image SLES12-SP5-Azure-Basic-On-Demand:runc-1.1.12-16.46.1
Image SLES12-SP5-Azure-Standard-On-Demand:runc-1.1.12-16.46.1
Image SLES12-SP5-EC2-ECS-On-Demand:runc-1.1.12-16.46.1
Image SLES12-SP5-EC2-On-Demand:runc-1.1.12-16.46.1

Ссылки