Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
HIGH 7.0 Go

Opencontainers runc Incorrect Authorization vulnerability

GHSA-vpvm-3wq2-2wvm · CVE-2023-27561 · GO-2023-1627

Published · Modified

Description

runc 1.0.0-rc95 through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes