runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Runc | Linuxfoundation | * | 0.1.1 (including) |
Runc | Linuxfoundation | 1.0.0-rc1 (including) | 1.0.0-rc1 (including) |
Runc | Linuxfoundation | 1.0.0-rc2 (including) | 1.0.0-rc2 (including) |
Runc | Linuxfoundation | 1.0.0-rc3 (including) | 1.0.0-rc3 (including) |
Runc | Linuxfoundation | 1.0.0-rc4 (including) | 1.0.0-rc4 (including) |
Runc | Linuxfoundation | 1.0.0-rc5 (including) | 1.0.0-rc5 (including) |
Runc | Linuxfoundation | 1.0.0-rc6 (including) | 1.0.0-rc6 (including) |
Runc | Linuxfoundation | 1.0.0-rc7 (including) | 1.0.0-rc7 (including) |
Runc | Linuxfoundation | 1.0.0-rc8 (including) | 1.0.0-rc8 (including) |
Runc | Linuxfoundation | 1.0.0-rc9 (including) | 1.0.0-rc9 (including) |
Red Hat Enterprise Linux 7 Extras | RedHat | runc-0:1.0.0-66.rc8.el7_7 | * |
Red Hat Enterprise Linux 8 | RedHat | container-tools:rhel8-8020020200324071414.0d58ad57 | * |
Red Hat OpenShift Container Platform 4.1 | RedHat | runc-0:1.0.0-63.rc8.rhaos4.1.git3cbe540.el8_0 | * |
Red Hat OpenShift Container Platform 4.2 | RedHat | runc-0:1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 | * |
Red Hat OpenShift Container Platform 4.3 | RedHat | runc-0:1.0.0-66.rc10.rhaos4.3.el7_8 | * |
Runc | Ubuntu | bionic | * |
Runc | Ubuntu | devel | * |
Runc | Ubuntu | disco | * |
Runc | Ubuntu | eoan | * |
Runc | Ubuntu | esm-apps/xenial | * |
Runc | Ubuntu | focal | * |
Runc | Ubuntu | groovy | * |
Runc | Ubuntu | hirsute | * |
Runc | Ubuntu | impish | * |
Runc | Ubuntu | jammy | * |
Runc | Ubuntu | kinetic | * |
Runc | Ubuntu | lunar | * |
Runc | Ubuntu | trusty | * |
Runc | Ubuntu | upstream | * |
Runc | Ubuntu | xenial | * |