USN-4960-1: runC vulnerability
Published May 19, 2021
·Updated
Etienne Champetier discovered that runC incorrectly checked mount targets. An attacker with a malicious container image could possibly mount the host filesystem into the container and escalate privileges.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/runc<1.0.0~rc93-0ubuntu1.1
1.0.0~rc93-0ubuntu1.1
Ubuntu Ubuntu=21.04
All of the following
ubuntu/runc<1.0.0~rc93-0ubuntu1~20.10.2
1.0.0~rc93-0ubuntu1~20.10.2
Ubuntu Ubuntu=20.10
All of the following
ubuntu/runc<1.0.0~rc93-0ubuntu1~20.04.2
1.0.0~rc93-0ubuntu1~20.04.2
Ubuntu Ubuntu=20.04
All of the following
ubuntu/runc<1.0.0~rc93-0ubuntu1~18.04.2
1.0.0~rc93-0ubuntu1~18.04.2
Ubuntu Ubuntu=18.04
Event History
May 19, 2021
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is USN-4960-1.
2
What is the title of this vulnerability?
The title of this vulnerability is USN-4960-1: runC vulnerability.
3
Who discovered this vulnerability?
Etienne Champetier discovered this vulnerability.
4
How can an attacker exploit this vulnerability?
An attacker with a malicious container image could possibly mount the host filesystem into the container and escalate privileges.
5
Which software versions are affected by this vulnerability?
The affected software versions are runc 1.0.0~rc93-0ubuntu1.1 on Ubuntu 21.04, runc 1.0.0~rc93-0ubuntu1~20.10.2 on Ubuntu 20.10, runc 1.0.0~rc93-0ubuntu1~20.04.2 on Ubuntu 20.04, and runc 1.0.0~rc93-0ubuntu1~18.04.2 on Ubuntu 18.04.