PT-2021-3856 · Unknown+6 · Kubernetes Containerd+5

Mcgowan

·

Published

2021-07-19

·

Updated

2024-08-21

·

CVE-2021-32760

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions containerd versions prior to 1.4.8 and 1.5.4
Description The issue is related to a bug in containerd that allows pulling and extracting a specially-crafted container image to result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process.
Recommendations For containerd versions prior to 1.4.8, update to version 1.4.8 as soon as possible. For containerd versions prior to 1.5.4, update to version 1.5.4 as soon as possible. As a temporary workaround, ensure that users only pull images from trusted sources. Consider using Linux security modules (LSMs) like SELinux and AppArmor to limit the files potentially affected by this bug through policies and profiles that prevent containerd from interacting with specific files.

Exploit

Fix

Incorrect Permission

Exposure of Resource to Wrong Sphere

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2459
ALT-PU-2021-2735
ALT-PU-2022-1248
AZL-6680
BDU:2021-04214
CVE-2021-32760
GHSA-C72P-9XMJ-RX3W
GO-2022-0921
MGASA-2021-0484
OPENSUSE-SU-2021:1081-1
OPENSUSE-SU-2021:1404-1
OPENSUSE-SU-2021:2412-1
OPENSUSE-SU-2021:3506-1
OPENSUSE-SU-2021_1081-1
OPENSUSE-SU-2021_1404-1
OPENSUSE-SU-2021_2412-1
OPENSUSE-SU-2021_3506-1
OPENSUSE-SU-2024:10693-1
OPENSUSE-SU-2024:11619-1
SUSE-SU-2021:2412-1
SUSE-SU-2021:2413-1
SUSE-SU-2021:3336-1
SUSE-SU-2021:3506-1
SUSE-SU-2021_2412-1
SUSE-SU-2021_2413-1
USN-5012-1
USN-5521-1

Affected Products

Alt Linux
Astra Linux
Kubernetes Containerd
Linuxmint
Suse
Ubuntu