blob: 9e59dbfc4e95c00cc4aa554cc975385f8a15c145 [file] [log] [blame]
id: GO-2024-2491
modules:
- module: github.com/opencontainers/runc
versions:
- introduced: 1.0.0-rc93
- fixed: 1.1.12
vulnerable_at: 1.1.11
packages:
- package: github.com/opencontainers/runc/libcontainer/utils
symbols:
- CloseExecFrom
skip_fix: cgo related fix error
- package: github.com/opencontainers/runc/libcontainer/cgroups
symbols:
- openFile
- prepareOpenat2
skip_fix: cgo related fix error
- package: github.com/opencontainers/runc/libcontainer
symbols:
- Container.start
- linuxSetnsInit.Init
- linuxStandardInit.Init
- Init
- finalizeNamespace
skip_fix: cgo related fix error
summary: |-
Container breakout through process.cwd trickery and leaked
fds in github.com/opencontainers/runc
cves:
- CVE-2024-21626
ghsas:
- GHSA-xr7r-f8xq-vfvv
credits:
- Rory McNamara from Snyk
- '@lifubang from acmcoder'
- Aleksa Sarai from SUSE
references:
- advisory: https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv
- fix: https://github.com/opencontainers/runc/commit/02120488a4c0fc487d1ed2867e901eeed7ce8ecf
- web: http://packetstormsecurity.com/files/176993/runc-1.1.11-File-Descriptor-Leak-Privilege-Escalation.html
source:
id: GHSA-xr7r-f8xq-vfvv
created: 2024-07-01T16:15:02.647859-04:00
review_status: REVIEWED
unexcluded: EFFECTIVELY_PRIVATE