Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53

Количество 53

fstec логотип

BDU:2025-14040

11 месяцев назад

Уязвимость инструмента для запуска изолированных контейнеров runc, связанная с состоянием гонки, разрешающим отслеживание ссылок, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 8.2
EPSS: Низкий
redos логотип

ROS-20260907-80-0032

23 дня назад

Уязвимость cni-plugins

CVSS3: 8.2
EPSS: Низкий
redos логотип

ROS-20260907-73-0031

23 дня назад

Уязвимость cni-plugins

CVSS3: 8.2
EPSS: Низкий
redos логотип

ROS-20251216-8003

10 месяцев назад

Уязвимость runc

CVSS3: 8.2
EPSS: Низкий
redos логотип

ROS-20251216-7354

10 месяцев назад

Уязвимость podman

CVSS3: 8.2
EPSS: Низкий
redos логотип

ROS-20251216-7350

10 месяцев назад

Уязвимость runc

CVSS3: 8.2
EPSS: Низкий
altlinux логотип

ALT-PU-2026-5699

6 месяцев назад

ALT-PU-2026-5699: package `cni-plugins` update to version 1.9.1-alt1

CVSS3: 8.2
EPSS: Низкий
altlinux логотип

ALT-PU-2025-15471

10 месяцев назад

ALT-PU-2025-15471: package `buildah` update to version 1.42.2-alt1

CVSS3: 8.2
EPSS: Низкий
altlinux логотип

ALT-PU-2025-15473

10 месяцев назад

ALT-PU-2025-15473: package `podman` update to version 5.7.0-alt1

CVSS3: 8.2
EPSS: Низкий
altlinux логотип

ALT-PU-2026-3295

7 месяцев назад

ALT-PU-2026-3295: package `runc` update to version 1.3.4-alt1

CVSS3: 8.2
EPSS: Низкий
altlinux логотип

ALT-PU-2025-15366

10 месяцев назад

ALT-PU-2025-15366: package `runc` update to version 1.4.0-alt1

CVSS3: 8.2
EPSS: Низкий
altlinux логотип

ALT-PU-2026-8716

3 месяца назад

ALT-PU-2026-8716: package `cri-o1.35` update to version 1.35.3-alt1

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2025-52881

11 месяцев назад

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-52881

11 месяцев назад

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2025-52881

11 месяцев назад

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-52881

10 месяцев назад

runc: LSM labels can be bypassed with malicious config using dummy procfs files

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2025-52881

11 месяцев назад

runc is a CLI tool for spawning and running containers according to th ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4076-1

11 месяцев назад

Security update for buildah

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4075-1

11 месяцев назад

Security update for buildah

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4074-1

11 месяцев назад

Security update for buildah

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-14040

Уязвимость инструмента для запуска изолированных контейнеров runc, связанная с состоянием гонки, разрешающим отслеживание ссылок, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 8.2
1%
Низкий
11 месяцев назад
redos логотип
ROS-20260907-80-0032

Уязвимость cni-plugins

CVSS3: 8.2
1%
Низкий
23 дня назад
redos логотип
ROS-20260907-73-0031

Уязвимость cni-plugins

CVSS3: 8.2
1%
Низкий
23 дня назад
redos логотип
ROS-20251216-8003

Уязвимость runc

CVSS3: 8.2
1%
Низкий
10 месяцев назад
redos логотип
ROS-20251216-7354

Уязвимость podman

CVSS3: 8.2
1%
Низкий
10 месяцев назад
redos логотип
ROS-20251216-7350

Уязвимость runc

CVSS3: 8.2
1%
Низкий
10 месяцев назад
altlinux логотип
ALT-PU-2026-5699

ALT-PU-2026-5699: package `cni-plugins` update to version 1.9.1-alt1

CVSS3: 8.2
1%
Низкий
6 месяцев назад
altlinux логотип
ALT-PU-2025-15471

ALT-PU-2025-15471: package `buildah` update to version 1.42.2-alt1

CVSS3: 8.2
1%
Низкий
10 месяцев назад
altlinux логотип
ALT-PU-2025-15473

ALT-PU-2025-15473: package `podman` update to version 5.7.0-alt1

CVSS3: 8.2
10 месяцев назад
altlinux логотип
ALT-PU-2026-3295

ALT-PU-2026-3295: package `runc` update to version 1.3.4-alt1

CVSS3: 8.2
7 месяцев назад
altlinux логотип
ALT-PU-2025-15366

ALT-PU-2025-15366: package `runc` update to version 1.4.0-alt1

CVSS3: 8.2
10 месяцев назад
altlinux логотип
ALT-PU-2026-8716

ALT-PU-2026-8716: package `cri-o1.35` update to version 1.35.3-alt1

CVSS3: 8.2
3 месяца назад
ubuntu логотип
CVE-2025-52881

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.

CVSS3: 7.5
1%
Низкий
11 месяцев назад
redhat логотип
CVE-2025-52881

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.

CVSS3: 8.2
1%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-52881

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.

CVSS3: 7.5
1%
Низкий
11 месяцев назад
msrc логотип
CVE-2025-52881

runc: LSM labels can be bypassed with malicious config using dummy procfs files

CVSS3: 7.3
1%
Низкий
10 месяцев назад
debian логотип
CVE-2025-52881

runc is a CLI tool for spawning and running containers according to th ...

CVSS3: 7.5
1%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4076-1

Security update for buildah

1%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4075-1

Security update for buildah

1%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4074-1

Security update for buildah

1%
Низкий
11 месяцев назад

Уязвимостей на страницу