VDB
Sign up
MEDIUM5.4

GHSA-mc76-5925-c5p6

Link Following in github.com/containers/common

Quick fix

GHSA-mc76-5925-c5p6 — github.com/containers/common: upgrade to the fixed version with the command below.

go get github.com/containers/common@v0.60.4

Details

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/containers/common
Introduced in: 0Fixed in: 0.60.4
Fixgo get github.com/containers/common@v0.60.4

References