Skip to content

runc CVE-2021-30465

High
tjkirch published GHSA-f38j-qm72-5cp9 May 19, 2021

Package

runc (bottlerocket)

Affected versions

< 1.1.1

Patched versions

1.1.1

Description

runc 1.0.0-rc93 and earlier are vulnerable to a symlink exchange attack whereby an attacker can request a seemingly-innocuous container configuration that actually results in the host filesystem being bind-mounted into the container (allowing for a container escape).

GHSA-c3xm-pvg7-gh7r

Severity

High

CVE ID

CVE-2021-30465

Weaknesses

No CWEs