CVE-2024-21626
EUVD-2024-045931.01.2024, 22:15
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| linuxfoundation | runc | 𝑥 < 1.1.12 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | OCP-Tools-4.15-RHEL-8 | 0:2.440.3.1718879390-3.el8 ≤ 𝑥 < * | ADP |
| Red Hat | OCP-Tools-4.15-RHEL-8 | 0:4.15.1718879538-1.el8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 7 Extras | 0:1.0.0-70.rc10.el7_9 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 7 Extras | 2:1.13.1-210.git7d71120.el7_9 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8 | 8090020240201111813.d7b6f4b7 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8 | 8090020240201111839.d7b6f4b7 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | 8020020240206120705.28c38760 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | 8020020240206120705.28c38760 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | 8020020240206120705.28c38760 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 8040020240207051234.c0c392d5 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | 8040020240207051234.c0c392d5 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | 8040020240207051234.c0c392d5 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | 8060020240205133014.3b538bd8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | 8060020240206151655.3b538bd8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | 8080020240206143933.0f77c1b7 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 4:1.1.12-1.el9_3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | 4:1.1.12-1.el9_0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | 4:1.1.12-1.el9_2 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.11 | 3:1.1.2-3.1.rhaos4.11.el8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 3:1.1.6-5.1.rhaos4.12.el8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.12 | v4.12.0-202503030130.p0.g7c2a284.assembly.stream.el8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 4:1.1.12-1.rhaos4.13.el8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | v4.13.0-202503111300.p0.gb379980.assembly.stream.el8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 4:1.1.12-1.rhaos4.14.el8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | v4.14.0-202503060906.p0.gb03f3f5.assembly.stream.el8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 0:4.14.42-202411280904.p0.gcf4d04f.assembly.4.14.42.el9 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | v4.15.0-202502171304.p0.gb74eb6d.assembly.stream.el8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 0:4.15.41-202412091343.p0.gcf9680e.assembly.4.15.41.el9 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 0:4.16.24-202411220522.p0.gcc4fedc.assembly.4.16.24.el9 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | v4.16.0-202501160405.p0.g300d9ad.assembly.stream.el9 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 0:4.17.7-202411280904.p0.g129334d.assembly.4.17.7.el9 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | v4.17.0-202501052337.p0.gbb33e13.assembly.stream.el9 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| runc |
|
Amazon Linux Releases
Azure Linux Releases
Azure Package | |||||
|---|---|---|---|---|---|
| buildah |
| ||||
| cri-o |
| ||||
| cri-tools |
| ||||
| kubernetes |
| ||||
| kubevirt |
| ||||
| moby-engine |
| ||||
| moby-runc |
| ||||
| podman |
|
Common Weakness Enumeration
- CWE-403 - Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')A process does not close sensitive file descriptors before invoking a child process, which allows the child to perform unauthorized I/O operations using those descriptors.
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References