CVE-2021-30465: Race Condition
Last updated 24 July 2024
Other sources
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-30465?
CVE-2021-30465 is a vulnerability in runc before version 1.0.0-rc95 that allows a container filesystem breakout via directory traversal.
How severe is CVE-2021-30465?
CVE-2021-30465 has a severity rating of 8.5 (high).
How can an attacker exploit CVE-2021-30465?
To exploit CVE-2021-30465, an attacker must be able to create multiple containers with a specific mount configuration and perform a symlink-exchange attack that relies on a race condition.
Which versions of runc are affected by CVE-2021-30465?
runc versions before 1.0.0-rc95 are affected by CVE-2021-30465.
Is there a fix for CVE-2021-30465?
Yes, upgrading to runc version 1.0.0-rc95 or later will fix CVE-2021-30465.