Database/Container, Kubernetes & orchestration
runc: Volume-mount race gives incorrect access control and privilege escalation to host
CVSS 7.0CVE-2019-19921Container, Kubernetes & orchestrationcurated
Impact
Volume-mount race gives incorrect access control and privilege escalation to host
Who can reach it
Any tenant workload able to spawn two containers with crafted mounts
What to do
Replace runc binary; drain node
References
Related entries
- runc: Regression of CVE-2019-19921: incorrect access control leading to privilege escalation via volume mountsCVE-2023-27561 · runcHigh
- runc: AppArmor bypass when /proc inside the container is symlinked with a specific mount configCVE-2023-28642 · runcMedium
- runc: Netlink bytemsg length integer overflow in libcontainer allows config injection / partial escapeCVE-2021-43784 · runcMedium
- runc: `runc exec --cap` created processes with non-empty inheritable capabilitiesCVE-2022-29162 · runcMedium
- runc: Rootless runc leaves /sys/fs/cgroup writable inside the containerCVE-2023-25809 · runcMedium
- runc: runc can be tricked into creating empty files/directories at arbitrary host locationsCVE-2024-45310 · runcLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.