Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
MEDIUM 6.1 Go

runc AppArmor bypass with symlinked /proc

GHSA-g2j6-57v7-gm8c · CVE-2023-28642 · GO-2023-1683

Published · Modified

Description

Impact

It was found that AppArmor, and potentially SELinux, can be bypassed when /proc inside the container is symlinked with a specific mount configuration.

Patches

Fixed in runc v1.1.5, by prohibiting symlinked /proc: https://github.com/opencontainers/runc/pull/3785

This PR fixes CVE-2023-27561 as well.

Workarounds

Avoid using an untrusted container image.

Ready to move

Start Securing

Free, no credit card | First findings in minutes