Skip to content

runc GHSA-g54h-m393-cpwq

Low
etungsten published GHSA-7w97-4245-cg37 Aug 18, 2020

Package

runc (bottlerocket)

Affected versions

< 0.5.0

Patched versions

0.5.0

Description

Users who created their own config.json objects and didn't prefix a deny-all rule ({"allow": false, "permissions": "rwm"} or equivalent) were not provided protection by the devices cgroup. This would allow malicious containers (with sufficient privileges) to create arbitrary device inodes (assuming they have CAP_MKNOD) and operate on any device inodes they may have access to (assuming they have regular Unix DAC permissions).

GHSA-g54h-m393-cpwq

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs