Описание
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 1.1.4-0ubuntu1~18.04.2 |
devel | released | 1.1.4-0ubuntu4 |
esm-apps/bionic | released | 1.1.4-0ubuntu1~18.04.2 |
esm-apps/xenial | released | 1.0.0~rc7+git20190403.029124da-0ubuntu1~16.04.4+esm4 |
esm-infra/focal | not-affected | 1.1.4-0ubuntu1~20.04.3 |
focal | released | 1.1.4-0ubuntu1~20.04.3 |
jammy | released | 1.1.4-0ubuntu1~22.04.3 |
kinetic | released | 1.1.4-0ubuntu1~22.10.3 |
lunar | released | 1.1.4-0ubuntu3.1 |
trusty | ignored | end of standard support |
Показывать по
Ссылки на источники
EPSS
7 High
CVSS3
Связанные уязвимости
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
runc through 1.1.4 has Incorrect Access Control leading to Escalation ...
Opencontainers runc Incorrect Authorization vulnerability
EPSS
7 High
CVSS3