MEDIUM6.1
GHSA-g2j6-57v7-gm8c
runc AppArmor bypass with symlinked /proc
Quick fix
GHSA-g2j6-57v7-gm8c — github.com/opencontainers/runc: upgrade to the fixed version with the command below.
go get github.com/opencontainers/runc@v1.1.5Details
### Impact It was found that AppArmor, and potentially SELinux, can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration.
### Patches Fixed in runc v1.1.5, by prohibiting symlinked `/proc`: https://github.com/opencontainers/runc/pull/3785
This PR fixes CVE-2023-27561 as well.
### Workarounds Avoid using an untrusted container image.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/opencontainers/runc
Introduced in:
0Fixed in: 1.1.5Fix
go get github.com/opencontainers/runc@v1.1.5References
- https://github.com/opencontainers/runc/security/advisories/GHSA-g2j6-57v7-gm8c[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-28642[ADVISORY]
- https://github.com/opencontainers/runc/pull/3785[WEB]
- https://github.com/opencontainers/runc[PACKAGE]
- https://security.netapp.com/advisory/ntap-20241206-0005[WEB]