CVE-2024-21626

EUVD-2024-0459
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.
File Descriptor Leak
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
linuxfoundationrunc
𝑥
< 1.1.12
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatOCP-Tools-4.15-RHEL-8
0:2.440.3.1718879390-3.el8 ≤
𝑥
< *
ADP
Red HatOCP-Tools-4.15-RHEL-8
0:4.15.1718879538-1.el8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 7 Extras
0:1.0.0-70.rc10.el7_9 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 7 Extras
2:1.13.1-210.git7d71120.el7_9 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
8090020240201111813.d7b6f4b7 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
8090020240201111839.d7b6f4b7 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.2 Advanced Update Support
8020020240206120705.28c38760 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.2 Telecommunications Update Service
8020020240206120705.28c38760 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.2 Update Services for SAP Solutions
8020020240206120705.28c38760 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
8040020240207051234.c0c392d5 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Telecommunications Update Service
8040020240207051234.c0c392d5 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Update Services for SAP Solutions
8040020240207051234.c0c392d5 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support
8060020240205133014.3b538bd8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support
8060020240206151655.3b538bd8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Extended Update Support
8080020240206143933.0f77c1b7 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
4:1.1.12-1.el9_3 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.0 Extended Update Support
4:1.1.12-1.el9_0 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.2 Extended Update Support
4:1.1.12-1.el9_2 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.11
3:1.1.2-3.1.rhaos4.11.el8 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.12
3:1.1.6-5.1.rhaos4.12.el8 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.12
v4.12.0-202503030130.p0.g7c2a284.assembly.stream.el8 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.13
4:1.1.12-1.rhaos4.13.el8 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.13
v4.13.0-202503111300.p0.gb379980.assembly.stream.el8 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.14
4:1.1.12-1.rhaos4.14.el8 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.14
v4.14.0-202503060906.p0.gb03f3f5.assembly.stream.el8 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.14
0:4.14.42-202411280904.p0.gcf4d04f.assembly.4.14.42.el9 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.15
v4.15.0-202502171304.p0.gb74eb6d.assembly.stream.el8 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.15
0:4.15.41-202412091343.p0.gcf9680e.assembly.4.15.41.el9 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.16
0:4.16.24-202411220522.p0.gcc4fedc.assembly.4.16.24.el9 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.16
v4.16.0-202501160405.p0.g300d9ad.assembly.stream.el9 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.17
0:4.17.7-202411280904.p0.g129334d.assembly.4.17.7.el9 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.17
v4.17.0-202501052337.p0.gbb33e13.assembly.stream.el9 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
runc
bookworm
1.1.5+ds1-1+deb12u1
fixed
bookworm (security)
1.1.5+ds1-1+deb12u1
fixed
bullseye
1.0.0~rc93+ds1-5+deb11u5
fixed
bullseye (security)
1.0.0~rc93+ds1-5+deb11u3
fixed
forky
1.3.3+ds1-2
fixed
sid
1.3.3+ds1-2
fixed
trixie
1.1.15+ds1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
runc
bionic
Fixed 1.1.4-0ubuntu1~18.04.2+esm1
released
focal
Fixed 1.1.7-0ubuntu1~20.04.2
released
jammy
Fixed 1.1.7-0ubuntu1~22.04.2
released
lunar
ignored
mantic
Fixed 1.1.7-0ubuntu2.2
released
noble
not-affected
trusty
ignored
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
runc
suse enterprise sap 15 SP3
1.1.12-150000.61.2
fixed
suse enterprise sap 15 SP4
1.1.12-150000.61.2
fixed
suse enterprise server 15 SP1
1.1.11-150000.58.1
fixed
suse enterprise server 15 SP2
1.1.12-150000.61.2
fixed
suse enterprise server 15 SP3
1.1.12-150000.61.2
fixed
suse enterprise server 15 SP4
1.1.12-150000.61.2
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
runc
RHEL 9
4:1.1.12-1.el9_3
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
runc
Amazon Linux 1
0:1.1.11-1.1.amzn1
fixed
Amazon Linux 2023
0:1.1.11-1.amzn2023.0.1
fixed
runc-debuginfo
Amazon Linux 1
0:1.1.11-1.1.amzn1
fixed
Amazon Linux 2023
0:1.1.11-1.amzn2023.0.1
fixed
runc-debugsource
Amazon Linux 2023
0:1.1.11-1.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
buildah
Azure Linux 3.0
0:1.41.4-2.azl3
fixed
cri-o
CBL-Mariner 2.0
0:1.21.7-3.cm2
fixed
cri-tools
Azure Linux 3.0
0:1.30.1-1.azl3
fixed
CBL-Mariner 2.0
0:1.28.0-5.cm2
fixed
kubernetes
Azure Linux 3.0
0:1.30.1-1.azl3
fixed
CBL-Mariner 2.0
0:0.0.0.cm2
fixed
kubevirt
Azure Linux 3.0
0:1.2.0-1.azl3
fixed
CBL-Mariner 2.0
0:0.59.0-14.cm2
fixed
moby-engine
Azure Linux 3.0
0:25.0.3-1.azl3
fixed
moby-runc
CBL-Mariner 2.0
0:1.1.9-4.cm2
fixed
podman
Azure Linux 3.0
0:5.6.1-2.azl3
fixed
References