PT-2020-10295 · Open Container Initiative+7 · Runc+7

Cyphar

·

Published

2016-08-03

·

Updated

2024-12-06

·

CVE-2019-19921

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions runc versions through 1.0.0-rc9 runc version 1.0.0-rc10 is not affected, as it contains the fix for this issue.
Description The issue is related to incorrect access control, leading to escalation of privileges. An attacker must be able to spawn two containers with custom volume-mount configurations and run custom images to exploit this. The vulnerability is related to libcontainer/rootfs linux.go. By crafting a malicious root filesystem, an attacker can trick runc into not correctly configuring the container's security labels and not correctly masking paths inside /proc, which contain potentially-sensitive information about the host. This could allow for direct attacks against the host.
Recommendations For runc versions through 1.0.0-rc9, update to version 1.0.0-rc10 to resolve the issue. As a temporary workaround, consider restricting access to custom volume mount configurations and custom images to minimize the risk of exploitation. Review access policies to ensure that untrusted users do not have high levels of control over container mount configuration.

Fix

Race Condition

Weakness Enumeration

Related Identifiers

ALSA-2020:1650
ALSA-2023:6380
ALSA-2023:6938
ALSA-2023:6939
ALT-PU-2016-1817
ALT-PU-2020-1252
ALT-PU-2020-2984
ALT-PU-2020-3026
CESA-2020_1650
CVE-2019-19921
DLA-3369-1
GHSA-FH74-HM69-RQJW
GO-2021-0087
MGASA-2020-0103
OPENSUSE-SU-2020:0219-1
OPENSUSE-SU-2020_0219-1
OPENSUSE-SU-2024:11358-1
RHSA-2020:0688
RHSA-2020:0695
RHSA-2020:0942
RHSA-2020:1485
RHSA-2020:1650
RHSA-2020_1650
RLSA-2020:1650
ROSA-SA-2024-2393
SUSE-SU-2020:0375-1
SUSE-SU-2020:0376-1
SUSE-SU-2020:0944-1
SUSE-SU-2020_0375-1
SUSE-SU-2020_0376-1
SUSE-SU-2020_0944-1
SUSE-SU-2021:1458-1
USN-4297-1
USN-6088-2

Affected Products

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Runc