Insecure object reference In github.com/opencontainers/runc/libcontainer
Description
Opencontainers runc Incorrect Authorization vulnerability
runc 1.0.0-rc95 through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | v1.1.5 | ||
debian 11 | 1.0.0~rc93+ds1-5+deb11u5 | ||
debian 12 | 1.1.5+ds1-1 | ||
go | 1.1.5 | ||
debian 13 | 1.1.5+ds1-1 | ||
debian 14 | 1.1.5+ds1-1 | ||
rpm rhel9 | 4:1.1.9-1.el9 | ||
rpm rhel7 | - | - | |
rpm rhel8 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16.