runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)
2020-02-12T15:15:12.210
2024-11-21T04:35:40.107
Modified
CVSSv3.1: 7.0 (HIGH)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | linuxfoundation | runc | ≤ 0.1.1 | Yes |
Application | linuxfoundation | runc | 1.0.0 | Yes |
Application | linuxfoundation | runc | 1.0.0 | Yes |
Application | linuxfoundation | runc | 1.0.0 | Yes |
Application | linuxfoundation | runc | 1.0.0 | Yes |
Application | linuxfoundation | runc | 1.0.0 | Yes |
Application | linuxfoundation | runc | 1.0.0 | Yes |
Application | linuxfoundation | runc | 1.0.0 | Yes |
Application | linuxfoundation | runc | 1.0.0 | Yes |
Application | linuxfoundation | runc | 1.0.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | opensuse | leap | 15.1 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 19.10 | Yes |
Application | redhat | openshift_container_platform | 4.1 | Yes |
Application | redhat | openshift_container_platform | 4.2 | Yes |