CVE-2021-33638: Run copy with container in a malicious directory may cause container escaping
When the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, the attacker can escape the container.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-33638?
CVE-2021-33638 is a vulnerability that occurs when the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, allowing the attacker to escape the container.
How does CVE-2021-33638 affect Openeuler Isula?
Openeuler Isula versions 2.0.8-20210518.144540, 2.0.18-10, and 2.1.2 are affected by CVE-2021-33638.
What is the severity of CVE-2021-33638?
CVE-2021-33638 has a severity rating of 8.4, which is considered high.
How can I fix CVE-2021-33638 in Openeuler Isula?
To fix CVE-2021-33638, update Openeuler Isula to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2021-33638?
More information about CVE-2021-33638 can be found at the following references: [Link 1](https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2023-1686), [Link 2](https://gitee.com/src-openeuler/iSulad/pulls/627/files), [Link 3](https://gitee.com/src-openeuler/iSulad/pulls/600/files)