TROYANOSYVIRUS
Voltar para CVEs

CVE-2023-27561

HIGH
7.0

Descricao

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

Detalhes CVE

Pontuacao CVSS v3.17.0
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueLOCAL
ComplexidadeHIGH
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado3/3/2023
Ultima modificacao12/6/2024
Fontenvd
Avistamentos honeypot0

Produtos afetados

debian:debian_linuxlinuxfoundation:runcredhat:enterprise_linuxredhat:openshift_container_platform

Fraquezas (CWE)

CWE-706CWE-706

Referencias

https://github.com/opencontainers/runc/issues/3751(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20241206-0004/(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.