PT-2023-3594 · Apparmor+11 · Apparmor+11
Ssst0N3
·
Published
2023-03-25
·
Updated
2025-08-08
·
CVE-2023-28642
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
runc versions prior to 1.1.5
Description
The issue is related to the incorrect handling of symbolic links before accessing a file, which allows an attacker to access confidential data, compromise its integrity, and cause a denial of service. It was found that AppArmor can be bypassed when
/proc inside the container is symlinked with a specific mount configuration.Recommendations
For versions prior to 1.1.5, upgrade to version 1.1.5 or later to fix the issue.
As a temporary workaround, consider avoiding the use of untrusted container images until the issue is resolved.
Restrict access to the
/proc endpoint inside the container to minimize the risk of exploitation.Exploit
Fix
Improper Preservation of Permissions
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apparmor
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Runc