https://seclists.org/oss-sec/2024/q3/237: CVE-2024-45310: runc can be tricked into cating empty files/dictories on host
Published Sep 3, 2024
·Updated
Affected Software
1 affected component
runc runc<=1.1.13, <=1.2.0-rc2
Frequently Asked Questions
1
What is the severity of CVE-2024-45310?
CVE-2024-45310 has a low severity rating.
2
How do I fix CVE-2024-45310?
To fix CVE-2024-45310, update runc to version 1.1.14 or later.
3
Which versions of runc are affected by CVE-2024-45310?
CVE-2024-45310 affects runc versions 1.1.13 and earlier as well as 1.2.0-rc2 and earlier.
4
What are the risks associated with CVE-2024-45310?
The risk associated with CVE-2024-45310 involves the potential for unauthorized empty files or directories to be created in arbitrary locations on the host filesystem.
5
Is there an embargo period for CVE-2024-45310?
No, the security patch for CVE-2024-45310 has been released without an embargo period.