Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 19

Количество 19

fstec логотип

BDU:2024-06891

около 2 лет назад

Уязвимость инструмента для запуска изолированных контейнеров Runc, связанная с состоянием гонки, разрешающим отслеживание ссылок, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 3.6
EPSS: Низкий
redos логотип

ROS-20241001-06

почти 2 года назад

Уязвимость runc

CVSS3: 3.6
EPSS: Низкий
ubuntu логотип

CVE-2024-45310

почти 2 года назад

runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with `os.MkdirAll`. While this could be used to create empty files, existing files would not be truncated. An attacker must have the ability to start containers using some kind of custom volume configuration. Containers using user namespaces are still affected, but the scope of places an attacker can create inodes can be significantly reduced. Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block this attack -- we suspect the industry standard SELinux policy may restrict this attack's scope but the exact scope of protection hasn't been analysed. This is exploitable using runc directly as well as through Docker and Kubernetes. The issue is fixed i...

CVSS3: 3.6
EPSS: Низкий
redhat логотип

CVE-2024-45310

почти 2 года назад

runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with `os.MkdirAll`. While this could be used to create empty files, existing files would not be truncated. An attacker must have the ability to start containers using some kind of custom volume configuration. Containers using user namespaces are still affected, but the scope of places an attacker can create inodes can be significantly reduced. Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block this attack -- we suspect the industry standard SELinux policy may restrict this attack's scope but the exact scope of protection hasn't been analysed. This is exploitable using runc directly as well as through Docker and Kubernetes. The issue is fixed i...

CVSS3: 3.6
EPSS: Низкий
nvd логотип

CVE-2024-45310

почти 2 года назад

runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with `os.MkdirAll`. While this could be used to create empty files, existing files would not be truncated. An attacker must have the ability to start containers using some kind of custom volume configuration. Containers using user namespaces are still affected, but the scope of places an attacker can create inodes can be significantly reduced. Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block this attack -- we suspect the industry standard SELinux policy may restrict this attack's scope but the exact scope of protection hasn't been analysed. This is exploitable using runc directly as well as through Docker and Kubernetes. The issue is fixed in r

CVSS3: 3.6
EPSS: Низкий
msrc логотип

CVE-2024-45310

больше 1 года назад

runc can be confused to create empty files/directories on the host

CVSS3: 3.6
EPSS: Низкий
debian логотип

CVE-2024-45310

почти 2 года назад

runc is a CLI tool for spawning and running containers according to th ...

CVSS3: 3.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1374-1

больше 1 года назад

Security update for runc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02198-2

около 1 года назад

Security update for runc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02198-1

около 1 года назад

Security update for runc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3324-1

почти 2 года назад

Security update for runc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3222-1

почти 2 года назад

Security update for runc

EPSS: Низкий
github логотип

GHSA-jfvp-7x6p-h2pv

почти 2 года назад

runc can be confused to create empty files/directories on the host

CVSS3: 3.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0479-1

6 месяцев назад

Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container, virt-synchronization-controller-container

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21379-1

14 дней назад

Security update for ctop

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21265-1

26 дней назад

Security update for cadvisor

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20281-1

5 месяцев назад

Security update for kubevirt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0439-1

6 месяцев назад

Security update for apptainer

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20834-1

2 месяца назад

Security update for apptainer

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-06891

Уязвимость инструмента для запуска изолированных контейнеров Runc, связанная с состоянием гонки, разрешающим отслеживание ссылок, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 3.6
0%
Низкий
около 2 лет назад
redos логотип
ROS-20241001-06

Уязвимость runc

CVSS3: 3.6
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-45310

runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with `os.MkdirAll`. While this could be used to create empty files, existing files would not be truncated. An attacker must have the ability to start containers using some kind of custom volume configuration. Containers using user namespaces are still affected, but the scope of places an attacker can create inodes can be significantly reduced. Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block this attack -- we suspect the industry standard SELinux policy may restrict this attack's scope but the exact scope of protection hasn't been analysed. This is exploitable using runc directly as well as through Docker and Kubernetes. The issue is fixed i...

CVSS3: 3.6
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-45310

runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with `os.MkdirAll`. While this could be used to create empty files, existing files would not be truncated. An attacker must have the ability to start containers using some kind of custom volume configuration. Containers using user namespaces are still affected, but the scope of places an attacker can create inodes can be significantly reduced. Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block this attack -- we suspect the industry standard SELinux policy may restrict this attack's scope but the exact scope of protection hasn't been analysed. This is exploitable using runc directly as well as through Docker and Kubernetes. The issue is fixed i...

CVSS3: 3.6
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-45310

runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with `os.MkdirAll`. While this could be used to create empty files, existing files would not be truncated. An attacker must have the ability to start containers using some kind of custom volume configuration. Containers using user namespaces are still affected, but the scope of places an attacker can create inodes can be significantly reduced. Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block this attack -- we suspect the industry standard SELinux policy may restrict this attack's scope but the exact scope of protection hasn't been analysed. This is exploitable using runc directly as well as through Docker and Kubernetes. The issue is fixed in r

CVSS3: 3.6
0%
Низкий
почти 2 года назад
msrc логотип
CVE-2024-45310

runc can be confused to create empty files/directories on the host

CVSS3: 3.6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-45310

runc is a CLI tool for spawning and running containers according to th ...

CVSS3: 3.6
0%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2025:1374-1

Security update for runc

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02198-2

Security update for runc

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02198-1

Security update for runc

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3324-1

Security update for runc

0%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3222-1

Security update for runc

0%
Низкий
почти 2 года назад
github логотип
GHSA-jfvp-7x6p-h2pv

runc can be confused to create empty files/directories on the host

CVSS3: 3.6
0%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2026:0479-1

Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container, virt-synchronization-controller-container

6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21379-1

Security update for ctop

14 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21265-1

Security update for cadvisor

26 дней назад
suse-cvrf логотип
openSUSE-SU-2026:20281-1

Security update for kubevirt

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0439-1

Security update for apptainer

6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20834-1

Security update for apptainer

2 месяца назад

Уязвимостей на страницу