VDB
Sign up
HIGH8.6

GHSA-g5p6-327m-3fxx

Talos Linux ships runc vulnerable to the escape to the host attack

Quick fix

GHSA-g5p6-327m-3fxx — github.com/siderolabs/talos: upgrade to the fixed version with the command below.

go get github.com/siderolabs/talos@v1.6.4

Details

### Impact

Snyk has discovered a vulnerability in all versions of runc <=1.1.11, as used by the Docker engine, along with other containerization technologies such as Kubernetes. Exploitation of this issue can result in container escape to the underlying host OS, either through executing a malicious image or building an image using a malicious Dockerfile or upstream image (i.e., when using FROM). This issue has been assigned the CVE-2024-21626.

### Patches

`runc` runtime was updated to 1.1.12 in Talos v1.5.6 and v1.6.4.

### Workarounds

Inspect the workloads running on the cluster to make sure they are not trying to exploit the vulnerability.

### References

* [CVE-2024-21626](https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv) * [Vulnerability: runc process.cwd and leaked fds container breakout](https://snyk.io/blog/cve-2024-21626-runc-process-cwd-container-breakout/)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/siderolabs/talos
Introduced in: 1.6.0Fixed in: 1.6.4
Fixgo get github.com/siderolabs/talos@v1.6.4
Go/github.com/siderolabs/talos
Introduced in: 0Fixed in: 1.5.6
Fixgo get github.com/siderolabs/talos@v1.5.6

References