TROYANOSYVIRUS
Retour aux CVEs

CVE-2023-27561

HIGH
7.0

Description

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

Details CVE

Score CVSS v3.17.0
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteHIGH
Privileges requisLOW
Interaction utilisateurNONE
Publie3/3/2023
Derniere modification12/6/2024
Sourcenvd
Observations honeypot0

Produits affectes

debian:debian_linuxlinuxfoundation:runcredhat:enterprise_linuxredhat:openshift_container_platform

Faiblesses (CWE)

CWE-706CWE-706

References

https://github.com/opencontainers/runc/issues/3751(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20241206-0004/(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.