VDB
Sign up
HIGH7.5

GHSA-fgv8-vj5c-2ppq

Incorrect Authorization in runc

Quick fix

GHSA-fgv8-vj5c-2ppq — github.com/opencontainers/runc: upgrade to the fixed version with the command below.

go get github.com/opencontainers/runc@v1.0.0-rc8.0.20190930145003-cad42f6e0932

Details

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/opencontainers/runc
Introduced in: 0Fixed in: 1.0.0-rc8.0.20190930145003-cad42f6e0932
Fixgo get github.com/opencontainers/runc@v1.0.0-rc8.0.20190930145003-cad42f6e0932
Go/github.com/opencontainers/selinux
Introduced in: 0Fixed in: 1.3.1-0.20190929122143-5215b1806f52
Fixgo get github.com/opencontainers/selinux@v1.3.1-0.20190929122143-5215b1806f52

References