REDHAT-BUG-2404715: High severity runc runc vulnerability
A flaw was found in runc. This attack is a more sophisticated variant of CVE-2019-16884, which was a flaw that allowed an attacker to trick runc into writing the LSM process labels for a container process into a dummy tmpfs file and thus not apply the correct LSM labels to the container process. The mitigation applied for CVE-2019-16884 was fairly limited and effectively only caused runc to verify that when we write LSM labels that those labels are actual procfs files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2404715?
The severity of REDHAT-BUG-2404715 is considered high due to its impact on the security of container processes.
How do I fix REDHAT-BUG-2404715?
To mitigate REDHAT-BUG-2404715, please update your runc to the latest version that addresses this vulnerability.
What systems are affected by REDHAT-BUG-2404715?
REDHAT-BUG-2404715 affects systems utilizing runc as part of their container runtime environment.
Is REDHAT-BUG-2404715 a new vulnerability?
No, REDHAT-BUG-2404715 is a more sophisticated variant of the previously identified CVE-2019-16884.
What type of attacks can REDHAT-BUG-2404715 allow?
REDHAT-BUG-2404715 can allow attackers to exploit container processes by manipulating LSM process labels.