Database/Container, Kubernetes & orchestration
runc: AppArmor bypass when /proc inside the container is symlinked with a specific mount config
CVSS 6.1CVE-2023-28642Container, Kubernetes & orchestrationcurated
Impact
AppArmor bypass when /proc inside the container is symlinked with a specific mount config
Who can reach it
Malicious image or tenant-controlled pod spec
What to do
Replace runc binary; drain node
References
Related entries
- runc: Netlink bytemsg length integer overflow in libcontainer allows config injection / partial escapeCVE-2021-43784 · runcMedium
- runc: `runc exec --cap` created processes with non-empty inheritable capabilitiesCVE-2022-29162 · runcMedium
- runc: Rootless runc leaves /sys/fs/cgroup writable inside the containerCVE-2023-25809 · runcMedium
- runc: runc can be tricked into creating empty files/directories at arbitrary host locationsCVE-2024-45310 · runcLow
- runc: setupPtmx/setupDev rootfs setup flaw during container rootfs constructionCVE-2026-41579 · runcLow
- runc: Host runc binary overwritten from inside a containerCVE-2019-5736 · runcHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.