logo

Database

Lack of data validation In runc

Description

A flaw was found in runc, a tool used to run containers. A malicious container image, crafted with a specific type of symbolic link in its /dev directory, can deceive runc. This deception could lead to the deletion of certain files or the creation of predefined symbolic links on the host system where the container is running. This vulnerability, known as Improper Neutralization of Special Elements used in a Path (CWE-61), primarily affects container runtimes like Podman and containerd that utilize runc, potentially compromising the integrity of the host's filesystem.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions