File and Directory Vulnerability in runc Container Runtime by OpenContainers
CVE-2024-45310
What is CVE-2024-45310?
A vulnerability in runc allows an attacker to exploit a race condition when creating empty files or directories in arbitrary locations on the host filesystem by utilizing shared volumes between containers. This affects runc versions 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier. Although this vulnerability does not truncate existing files, it poses a risk if an attacker can start containers with custom volume configurations. The potential to create inodes is somewhat mitigated with user namespaces, limiting the locations to world-writable directories. Implementation of strict LSM policies like SELinux or AppArmor may also help restrict this vulnerability's impact, although their effectiveness varies and has not been exhaustively tested.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
runc < 1.1.14 < 1.1.14
runc >= 1.2.0-rc-1, < 1.2.0-rc.3 < 1.2.0-rc-1, 1.2.0-rc.3
References
CVSS V3.1
Timeline
Vulnerability published
