Description
A flaw was found in runc, a tool used to run containers. A malicious container image, crafted with a specific type of symbolic link in its /dev directory, can deceive runc. This deception could lead to the deletion of certain files or the creation of predefined symbolic links on the host system where the container is running. This vulnerability, known as Improper Neutralization of Special Elements used in a Path (CWE-61), primarily affects container runtimes like Podman and containerd that utilize runc, potentially compromising the integrity of the host's filesystem.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 11 | | =1.0.0+ds1-1 || =1.0.0~rc93+ds1-5 || =1.0.0~rc93+ds1-5+deb11u1 || =1.0.0~rc93+ds1-5+deb11u2 || =1.0.0~rc93+ds1-5+deb11u3 || =1.0.0~rc93+ds1-5+deb11u4 || =1.0.0~rc93+ds1-5+deb11u5 || =1.0.0~rc93.144.g6538f9f2+ds1-1 || =1.0.0~rc94+ds1-1 || =1.0.0~rc94+ds1-2 || =1.0.0~rc95.86.g2f8e8e9d+ds1-1 || =1.0.1+ds1-1 || =1.0.1+ds1-2 || =1.0.2+ds1-1 || =1.0.2+ds1-2 || =1.0.3+ds1-1 || =1.1.0+ds1-1 || =1.1.0~rc.1+ds1-1 || =1.1.1+ds1-1 || =1.1.10+ds1-1 || =1.1.12+ds1-1 || =1.1.12+ds1-2 || =1.1.12+ds1-3 || =1.1.12+ds1-4 || =1.1.12+ds1-5 || =1.1.12+ds1-5.1 || =1.1.15+ds1-1 || =1.1.15+ds1-2 || =1.1.3+ds1-1 || =1.1.3+ds1-2 || =1.1.3+ds1-3 || =1.1.3+ds1-4 || =1.1.3+ds1-5 || =1.1.3+ds1-6 || =1.1.3+ds1-7 || =1.1.4+ds1-1 || =1.1.5+ds1-1 || =1.1.5+ds1-2 || =1.1.5+ds1-3 || =1.1.5+ds1-4 || =1.1.5+ds1-5 || =1.3.0+ds1-1 || =1.3.0+ds1-2 || =1.3.0+ds1-3 || =1.3.0+ds1-4 || =1.3.2+ds1-1 || =1.3.3+ds1-1 || =1.3.3+ds1-2 || =1.3.3+ds1-3 || =1.3.5+ds1-1 || =1.3.6+ds1-1 || =1.4.3+ds1-1 | - |
 debian 13 | | =1.1.15+ds1-2 || =1.3.0+ds1-1 || =1.3.0+ds1-2 || =1.3.0+ds1-3 || =1.3.0+ds1-4 || =1.3.2+ds1-1 || =1.3.3+ds1-1 || =1.3.3+ds1-2 || =1.3.3+ds1-3 || =1.3.5+ds1-1 || =1.3.6+ds1-1 || =1.4.3+ds1-1 | - |
 debian 14 | | =1.1.15+ds1-2 || =1.3.0+ds1-1 || =1.3.0+ds1-2 || =1.3.0+ds1-3 || =1.3.0+ds1-4 || =1.3.2+ds1-1 || =1.3.3+ds1-1 || =1.3.3+ds1-2 || =1.3.3+ds1-3 || =1.3.5+ds1-1 || >=0 <1.3.6+ds1-1 | 1.3.6+ds1-1 |
 debian 12 | | =1.1.10+ds1-1 || =1.1.12+ds1-1 || =1.1.12+ds1-2 || =1.1.12+ds1-3 || =1.1.12+ds1-4 || =1.1.12+ds1-5 || =1.1.12+ds1-5.1 || =1.1.15+ds1-1 || =1.1.15+ds1-2 || =1.1.5+ds1-1 || =1.1.5+ds1-1+deb12u1 || =1.1.5+ds1-2 || =1.1.5+ds1-3 || =1.1.5+ds1-4 || =1.1.5+ds1-5 || =1.3.0+ds1-1 || =1.3.0+ds1-2 || =1.3.0+ds1-3 || =1.3.0+ds1-4 || =1.3.2+ds1-1 || =1.3.3+ds1-1 || =1.3.3+ds1-2 || =1.3.3+ds1-3 || =1.3.5+ds1-1 || =1.3.6+ds1-1 || =1.4.3+ds1-1 | - |
 go | | >=0 <1.3.6 || >=1.4.0 <1.4.3 || >=1.5.0-rc.1 <1.5.0-rc.3 | 1.3.6, 1.4.3, 1.5.0-rc.3 |
 rpm rhel9 | | - | - |
 rpm rhel8 | | - | - |