REDHAT-BUG-2404705: High severity runc runc vulnerability
A flaw was found in runc. This flaw exploits an issue with how masked paths are implementedin runc. When masking files, runc will bind-mount the container's /dev/null inode on top of the file. However, if an attacker can replace /dev/null with a symlink to some other procfs file, runc will instead bind-mount the symlink target read-write.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2404705?
The severity of REDHAT-BUG-2404705 is considered high due to potential privilege escalation risks.
How do I fix REDHAT-BUG-2404705?
To fix REDHAT-BUG-2404705, upgrade to the patched version of runc provided by your Linux distribution.
How does REDHAT-BUG-2404705 impact container security?
REDHAT-BUG-2404705 can allow an attacker to manipulate container file paths, leading to unauthorized access to container files.
Which versions of runc are affected by REDHAT-BUG-2404705?
All versions of runc prior to the security patch addressing REDHAT-BUG-2404705 are affected.
Can REDHAT-BUG-2404705 be exploited remotely?
Yes, if an attacker has access to the container, they can exploit REDHAT-BUG-2404705 locally to escalate privileges.