An issue was discovered in crun before 0.10.5. With a crafted image, it doesnt correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and libcrun/chroot_realpath.c.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Crun | Crun_project | * | 0.10.5 (excluding) |
Crun | Ubuntu | trusty | * |