First published: Wed Mar 29 2023(Updated: )
Last updated 24 July 2024
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/runc | <1.1.5 | 1.1.5 |
Linuxfoundation Runc | <1.1.5 | |
debian/runc | <=1.0.0~rc93+ds1-5+deb11u3 | 1.0.0~rc93+ds1-5+deb11u5 1.1.5+ds1-1+deb12u1 1.1.15+ds1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25809 is a vulnerability in the runc CLI tool that allows rootless runc to make /sys/fs/cgroup writable under certain conditions.
CVE-2023-25809 affects runc by making /sys/fs/cgroup writable when runc is executed inside the user namespace and the config.json does not specify the cgroup.
CVE-2023-25809 has a severity rating of medium.
To fix CVE-2023-25809 on Red Hat, update runc to version 1.1.5 or newer.
To fix CVE-2023-25809 on Ubuntu 18.04, update runc to version 1.1.4-0ubuntu1~18.04.2 or newer.