runc Vulnerability Allows Container Escape and Host File Access
Key Information
- Vendor
- Opencontainers
- Status
- Runc
- Vendor
- CVE Published:
- 31 January 2024
Badges
Summary
CVE-2024-21626 is a vulnerability in all versions of runc <=1.1.11, used by Docker engine and other containerization technologies, allowing for container escape and access to the host OS. Exploiting this issue can result in unauthorized access to the underlying host's file system, with potential for further system compromise. The vulnerability has been addressed in runc 1.1.12, and organizations are advised to update their container infrastructure to mitigate the risk. The Snyk team has created runtime and static detection tools to help assess the vulnerability in container environments. Organizations should consider immediate action to update runc and associated technologies to prevent exploitation of this vulnerability.
Affected Version(s)
runc = >=v1.0.0-rc93, < 1.1.12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Illustrate runC Escape Vulnerability CVE-2024–21626 with my tests
For runC, a container runtime component, published version 1.1.12 to fix CVE-2024-21626 at 31, Jan 2024, which leads to escaping from containers. The range of affected versions are >= v1.0.0-rc93…
10 months ago
runc working directory breakout (CVE-2024-21626)
An analysis of CVE-2024-21626 which is a vulnerability in runc that allows for container breakout.
10 months ago
Leaky Vessels: Deep Dive on Container Escape Vulnerabilities | Wiz Blog
'Leaky Vessels' is a set of container escape vulnerabilities affecting runC and BuildKit. Learn how they work and what security teams can do to mitigate them.
10 months ago
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 👾
Exploit exists.
- 🔥
Vulnerability reached the number 1 worldwide trending spot.
Vulnerability started trending.
First article discovered by Snyk
Vulnerability published.
Vulnerability Reserved.