VDB
Sign up
HIGH7.0

GHSA-vpvm-3wq2-2wvm

Opencontainers runc Incorrect Authorization vulnerability

Quick fix

GHSA-vpvm-3wq2-2wvm — github.com/opencontainers/runc: upgrade to the fixed version with the command below.

go get github.com/opencontainers/runc@v1.1.5

Details

runc 1.0.0-rc95 through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to `libcontainer/rootfs_linux.go`. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/opencontainers/runc
Introduced in: 1.0.0-rc95Fixed in: 1.1.5
Fixgo get github.com/opencontainers/runc@v1.1.5

References