Aller au contenu principal
HIGH

CVE-2024-21626

CVSS v3

8.6

HIGH

Score EPSS

5.8 %

probabilité d’exploitation

CISA KEV

Non

exploitation connue

Exploitation

statut SSVC

Description

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

Détails techniques

Publiée le
2024-01-31

Questions fréquentes

Qu’est-ce que CVE-2024-21626 ?

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

CVE-2024-21626 est-elle activement exploitée ?

Aucune exploitation active de CVE-2024-21626 n’est confirmée. Le score EPSS est de 5.8 %, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2024-21626 ?

CVE-2024-21626 a un score de base CVSS v3 de 8.6 (gravité HIGH).

CVE-2024-21626 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 500 vérifications gratuites par mois · Clé API gratuite