TROYANOSYVIRUS
Back to CVEs

CVE-2023-27561

HIGH
7.0

Description

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

CVE Details

CVSS v3.1 Score7.0
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
Published3/3/2023
Last Modified12/6/2024
Sourcenvd
Honeypot Sightings0

Affected Products

debian:debian_linuxlinuxfoundation:runcredhat:enterprise_linuxredhat:openshift_container_platform

Weaknesses (CWE)

CWE-706CWE-706

References

https://github.com/opencontainers/runc/issues/3751(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20241206-0004/(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.