CVE-2019-19921
published 2020-02-12CVE-2019-19921: runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker…
PriorityP433high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.46%
36.8th percentile
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | runc | < runc 1.1.5+ds1-1 (bookworm) | runc 1.1.5+ds1-1 (bookworm) |
| debian | runc | < runc 1.0.0~rc10+dfsg1-1 (bookworm) | runc 1.0.0~rc10+dfsg1-1 (bookworm) |
| debian | runc | < runc 1.3.3+ds1-2 (forky) | runc 1.3.3+ds1-2 (forky) |
| github.com | opencontainers_runc | >= 0 < 1.2.8 | 1.2.8 |
| github.com | opencontainers_runc | >= 0 < 1.0.0-rc9.0.20200122160610-2fc03cc11c77 | 1.0.0-rc9.0.20200122160610-2fc03cc11c77 |
| github.com | opencontainers_runc | >= 1.0.0-rc95 < 1.1.5 | 1.1.5 |
| github.com | opencontainers_runc | >= 1.3.0-rc.1 < 1.3.3 | 1.3.3 |
| github.com | opencontainers_runc | >= 1.4.0-rc.1 < 1.4.0-rc.3 | 1.4.0-rc.3 |
| github.com | opencontainers_selinux | >= 0 < 1.13.0 | 1.13.0 |
| github.com | sylabs_singularity_v4 | >= 0 < 4.1.11 | 4.1.11 |
| github.com | sylabs_singularity_v4 | >= 4.2.0-rc.1 < 4.3.5 | 4.3.5 |
| linuxfoundation | runc | < 1.2.8 | 1.2.8 |
| linuxfoundation | runc | < 1.1.5 | 1.1.5 |
| linuxfoundation | runc | <= 0.1.1 | — |
| linuxfoundation | runc | — | — |
| linuxfoundation | runc | — | — |
| linuxfoundation | runc | >= 0 < 1.0.0~rc93+ds1-5+deb11u5 | 1.0.0~rc93+ds1-5+deb11u5 |
| linuxfoundation | runc | >= 0 < 1.0.0~rc10+dfsg1-1 | 1.0.0~rc10+dfsg1-1 |
| linuxfoundation | runc | >= 0 < 1.1.5+ds1-1 | 1.1.5+ds1-1 |
| linuxfoundation | runc | >= 0 < 1.0.0~rc10+dfsg1-1 | 1.0.0~rc10+dfsg1-1 |
| linuxfoundation | runc | >= 0 < 1.1.5+ds1-1 | 1.1.5+ds1-1 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
ghsa7.3HIGH
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Singluarity ineffectively applies selinux / apparmor LSM process labels
ghsa·2025-12-02·CVSS 7.3
CVE-2025-64750 [HIGH] CWE-61 Singluarity ineffectively applies selinux / apparmor LSM process labels
Singluarity ineffectively applies selinux / apparmor LSM process labels
### Impact
_**Native Mode (default)**_
Singularity's default native runtime allows users to apply restrictions to container processes using the apparmor or selinux Linux Security Modules (LSMs), via the `--security selinux:` or `--security apparmor:` flags.
LSM labels are written to process or thread `attrs/exec` under `/proc`. If a user relies on LSM restrictions to prevent malicious operations then, under certain circumstances, an attacker can redirect the LSM label write operation so that it is ineffective. This requires:
* The attacker to cause the user to run a malicious container image that redirects the mount of `/proc` to the destination of a shared mount, either known to be configured on the target system
OSV
Singluarity ineffectively applies selinux / apparmor LSM process labels
osv·2025-12-02·CVSS 7.3
CVE-2025-64750 [HIGH] Singluarity ineffectively applies selinux / apparmor LSM process labels
Singluarity ineffectively applies selinux / apparmor LSM process labels
### Impact
_**Native Mode (default)**_
Singularity's default native runtime allows users to apply restrictions to container processes using the apparmor or selinux Linux Security Modules (LSMs), via the `--security selinux:` or `--security apparmor:` flags.
LSM labels are written to process or thread `attrs/exec` under `/proc`. If a user relies on LSM restrictions to prevent malicious operations then, under certain circumstances, an attacker can redirect the LSM label write operation so that it is ineffective. This requires:
* The attacker to cause the user to run a malicious container image that redirects the mount of `/proc` to the destination of a shared mount, either known to be configured on the target system
OSV
CVE-2025-52881: runc is a CLI tool for spawning and running containers according to the OCI specification
osv·2025-11-06·CVSS 7.0
CVE-2025-52881 [HIGH] CVE-2025-52881: runc is a CLI tool for spawning and running containers according to the OCI specification
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs f
GHSA
runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects
ghsa·2025-11-05·CVSS 7.0
CVE-2025-52881 [HIGH] CWE-363 runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects
runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects
### Impact ###
This attack is primarily a more sophisticated version of CVE-2019-19921, which was a flaw which allowed an attacker to trick runc into writing the LSM process labels for a container process into a dummy `tmpfs` file and thus not apply the correct LSM labels to the container process. The mitigation runc applied for CVE-2019-19921 was fairly limited and effectively only caused runc to verify that when runc writes LSM labels that those labels are actual procfs files.
Rather than using a fake `tmpfs` file for `/proc/self/attr/`, an attacker could instead (through various means) make `/proc/self/attr/` reference a real `procfs` file, but one that would still be a no-op (such a
OSV
runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects
osv·2025-11-05·CVSS 7.0
CVE-2025-52881 [HIGH] runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects
runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects
### Impact ###
This attack is primarily a more sophisticated version of CVE-2019-19921, which was a flaw which allowed an attacker to trick runc into writing the LSM process labels for a container process into a dummy `tmpfs` file and thus not apply the correct LSM labels to the container process. The mitigation runc applied for CVE-2019-19921 was fairly limited and effectively only caused runc to verify that when runc writes LSM labels that those labels are actual procfs files.
Rather than using a fake `tmpfs` file for `/proc/self/attr/`, an attacker could instead (through various means) make `/proc/self/attr/` reference a real `procfs` file, but one that would still be a no-op (such a
Kernel
Merge tag 'vfs-6.17-rc1.nsfs' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs
kernel_security·2025-07-28·CVSS 7.0
CVE-2019-19921 [HIGH] Merge tag 'vfs-6.17-rc1.nsfs' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs
Merge tag 'vfs-6.17-rc1.nsfs' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs
Pull namespace updates from Christian Brauner:
"This contains namespace updates. This time specifically for nsfs:
- Userspace heavily relies on the root inode numbers for namespaces
to identify the initial namespaces. That's already a hard
dependency. So we cannot change that anymore. Move the initial
inode numbers to a public header and align the only two namespaces
that currently don't do that with all the other namespaces.
- The root inode of /proc having a fixed inode number has been part
of the core kernel ABI since its inception, and recently some
userspace programs (mainly container runtimes) have started to
explicitly depend on this behaviour.
The main reason this is useful to userspace is th
Kernel
uapi: export PROCFS_ROOT_INO
kernel_security·2025-07-08·CVSS 7.0
CVE-2019-19921 [HIGH] uapi: export PROCFS_ROOT_INO
uapi: export PROCFS_ROOT_INO
The root inode of /proc having a fixed inode number has been part of the
core kernel ABI since its inception, and recently some userspace
programs (mainly container runtimes) have started to explicitly depend
on this behaviour.
The main reason this is useful to userspace is that by checking that a
suspect /proc handle has fstype PROC_SUPER_MAGIC and is PROCFS_ROOT_INO,
they can then use openat2(RESOLVE_{NO_{XDEV,MAGICLINK},BENEATH}) to
ensure that there isn't a bind-mount that replaces some procfs file with
a different one. This kind of attack has lead to security issues in
container runtimes in the past (such as CVE-2019-19921) and libraries
like libpathrs[1] use this feature of procfs to provide safe procfs
handling functions.
There was also some trailing
OSV
runc vulnerabilities
osv·2023-05-23·CVSS 7.0
CVE-2019-19921 [HIGH] runc vulnerabilities
runc vulnerabilities
USN-6088-1 fixed vulnerabilities in runC. This update provides
the corresponding updates for Ubuntu 16.04 LTS.
It was discovered that runC incorrectly performed access control when
mounting /proc to non-directories. An attacker could possibly use
this issue to escalate privileges.
(CVE-2019-19921)
Felix Wilhelm discovered that runC incorrecly handled netlink
messages. An attacker could possibly use
this issue to escalate privileges. (CVE-2021-43784)
Andrew G. Morgan discovered that runC incorrectly set
inherited process capabilities inside the container.
An attacker could possibly use this issue to
escalate privileges. (CVE-2022-29162)
Original advisory details:
It was discovered that runC incorrectly made /sys/fs/cgroup
writable when in rootless mode. An attacke
OSV
CVE-2023-27561: runc through 1
osv·2023-03-03·CVSS 7.0
CVE-2023-27561 [HIGH] CVE-2023-27561: runc through 1
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
OSV
Opencontainers runc Incorrect Authorization vulnerability
osv·2023-03-03·CVSS 7.0
CVE-2023-27561 [HIGH] Opencontainers runc Incorrect Authorization vulnerability
Opencontainers runc Incorrect Authorization vulnerability
runc 1.0.0-rc95 through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to `libcontainer/rootfs_linux.go`. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
GHSA
Opencontainers runc Incorrect Authorization vulnerability
ghsa·2023-03-03·CVSS 7.0
CVE-2023-27561 [HIGH] CWE-706 Opencontainers runc Incorrect Authorization vulnerability
Opencontainers runc Incorrect Authorization vulnerability
runc 1.0.0-rc95 through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to `libcontainer/rootfs_linux.go`. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
OSV
opencontainers runc contains procfs race condition with a shared volume mount
osv·2021-05-27
CVE-2019-19921 [MEDIUM] opencontainers runc contains procfs race condition with a shared volume mount
opencontainers runc contains procfs race condition with a shared volume mount
### Impact
By crafting a malicious root filesystem (with `/proc` being a symlink to a directory which was inside a volume shared with another running container), an attacker in control of both containers can trick `runc` into not correctly configuring the container's security labels and not correctly masking paths inside `/proc` which contain potentially-sensitive information about the host (or even allow for direct attacks against the host).
In order to exploit this bug, an untrusted user must be able to spawn custom containers with custom mount configurations (such that a volume is shared between two containers). It should be noted that we consider this to be a fairly high level of access for an untrusted use
GHSA
opencontainers runc contains procfs race condition with a shared volume mount
ghsa·2021-05-27
CVE-2019-19921 [MEDIUM] CWE-362 opencontainers runc contains procfs race condition with a shared volume mount
opencontainers runc contains procfs race condition with a shared volume mount
### Impact
By crafting a malicious root filesystem (with `/proc` being a symlink to a directory which was inside a volume shared with another running container), an attacker in control of both containers can trick `runc` into not correctly configuring the container's security labels and not correctly masking paths inside `/proc` which contain potentially-sensitive information about the host (or even allow for direct attacks against the host).
In order to exploit this bug, an untrusted user must be able to spawn custom containers with custom mount configurations (such that a volume is shared between two containers). It should be noted that we consider this to be a fairly high level of access for an untrusted use
OSV
Race condition in github.com/opencontainers/runc
osv·2021-04-14
CVE-2019-19921 Race condition in github.com/opencontainers/runc
Race condition in github.com/opencontainers/runc
A race while mounting volumes allows a possible symlink-exchange attack, allowing a user whom can start multiple containers with custom volume mount configurations to escape the container.
OSV
runc vulnerabilities
osv·2020-03-09·CVSS 7.5
CVE-2019-16884 [HIGH] runc vulnerabilities
runc vulnerabilities
It was discovered that runC incorrectly checked mount targets. An attacker
with a malicious container image could possibly mount over the /proc
directory and escalate privileges. This issue only affected Ubuntu 18.04
LTS. (CVE-2019-16884)
It was discovered that runC incorrectly performed access control. An
attacker could possibly use this issue to escalate privileges.
(CVE-2019-19921)
OSV
CVE-2019-19921: runc through 1
osv·2020-02-12·CVSS 7.0
CVE-2019-19921 [HIGH] CVE-2019-19921: runc through 1
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)
Red Hat
runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects
vendor_redhat·2025-11-05·CVSS 7.5
CVE-2025-52881 [HIGH] CWE-59 runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects
runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-
Debian
CVE-2025-52881: runc - runc is a CLI tool for spawning and running containers according to the OCI spec...
vendor_debian·2025·CVSS 7.0
CVE-2025-52881 [HIGH] CVE-2025-52881: runc - runc is a CLI tool for spawning and running containers according to the OCI spec...
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs f
Ubuntu
runC vulnerabilities
vendor_ubuntu·2023-05-23·CVSS 7.0
CVE-2022-29162 [HIGH] runC vulnerabilities
Title: runC vulnerabilities
Summary: Several security issues were fixed in runC.
USN-6088-1 fixed vulnerabilities in runC. This update provides
the corresponding updates for Ubuntu 16.04 LTS.
It was discovered that runC incorrectly performed access control when
mounting /proc to non-directories. An attacker could possibly use
this issue to escalate privileges.
(CVE-2019-19921)
Felix Wilhelm discovered that runC incorrecly handled netlink
messages. An attacker could possibly use
this issue to escalate privileges. (CVE-2021-43784)
Andrew G. Morgan discovered that runC incorrectly set
inherited process capabilities inside the container.
An attacker could possibly use this issue to
escalate privileges. (CVE-2022-29162)
Original advisory details:
It was discovered that runC incorrectly m
Microsoft
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges related to libcontainer/rootfs_linux.go. To exploit this an attacker must be able to spawn two containers with custo
vendor_msrc·2023-03-14·CVSS 7.0
CVE-2023-27561 [HIGH] CWE-706 runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges related to libcontainer/rootfs_linux.go. To exploit this an attacker must be able to spawn two containers with custo
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges related to libcontainer/rootfs_linux.go. To exploit this an attacker must be able to spawn two containers with custom volume-mount configurations and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/V
Red Hat
runc: volume mount race condition (regression of CVE-2019-19921)
vendor_redhat·2023-02-20·CVSS 7.0
CVE-2023-27561 [HIGH] CWE-41 runc: volume mount race condition (regression of CVE-2019-19921)
runc: volume mount race condition (regression of CVE-2019-19921)
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
A flaw was found in runc. An attacker who controls the container image for two containers that share a volume can race volume mounts during container initialization by adding a symlink to the rootfs that points to a directory on the volume.
Statement: The vulnerability in runc, related to Incorrect Access Control in libcontainer/rootfs_linux.go, is classified as a moderate severity issue due to its
Debian
CVE-2023-27561: runc - runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privile...
vendor_debian·2023·CVSS 7.0
CVE-2023-27561 [HIGH] CVE-2023-27561: runc - runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privile...
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
Scope: local
bookworm: resolved (fixed in 1.1.5+ds1-1)
bullseye: resolved (fixed in 1.0.0~rc93+ds1-5+deb11u5)
forky: resolved (fixed in 1.1.5+ds1-1)
sid: resolved (fixed in 1.1.5+ds1-1)
trixie: resolved (fixed in 1.1.5+ds1-1)
Ubuntu
runC vulnerabilities
vendor_ubuntu·2020-03-09·CVSS 7.5
CVE-2019-16884 [HIGH] runC vulnerabilities
Title: runC vulnerabilities
Summary: Several security issues were fixed in runc.
It was discovered that runC incorrectly checked mount targets. An attacker
with a malicious container image could possibly mount over the /proc
directory and escalate privileges. This issue only affected Ubuntu 18.04
LTS. (CVE-2019-16884)
It was discovered that runC incorrectly performed access control. An
attacker could possibly use this issue to escalate privileges.
(CVE-2019-19921)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation
vendor_redhat·2019-12-21·CVSS 7.0
CVE-2019-19921 [HIGH] CWE-41 runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation
runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)
A flaw was found in runc. An attacker who controls the container image for two containers that share a volume can race volume mounts during container initialization, by adding a symlink to the rootfs that points to a directory on the volume. The highest threat from this vulnerability is to data confidentiality and
Debian
CVE-2019-19921: runc - runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Pri...
vendor_debian·2019·CVSS 7.0
CVE-2019-19921 [HIGH] CVE-2019-19921: runc - runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Pri...
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)
Scope: local
bookworm: resolved (fixed in 1.0.0~rc10+dfsg1-1)
bullseye: resolved (fixed in 1.0.0~rc10+dfsg1-1)
forky: resolved (fixed in 1.0.0~rc10+dfsg1-1)
sid: resolved (fixed in 1.0.0~rc10+dfsg1-1)
trixie: resolved (fixed in 1.0.0~rc10+dfsg1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-19921 docker: runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation [openstack-rdo]
bugzilla·2020-01-29·CVSS 7.0
CVE-2019-19921 [HIGH] CVE-2019-19921 docker: runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation [openstack-rdo]
CVE-2019-19921 docker: runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg com
Bugzilla
CVE-2019-19921 runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation
bugzilla·2020-01-29·CVSS 7.0
CVE-2019-19921 [HIGH] CVE-2019-19921 runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation
CVE-2019-19921 runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation
An attacker who controls the container image for two containers that share a volume can race volume mounts during container initialization, by adding a symlink to the rootfs that points to a directory on the volume.
Upstream Issue:
https://github.com/opencontainers/runc/issues/2197
Discussion:
Created docker tracking bugs for this issue:
Affects: fedora-all [bug 1796110]
Affects: openstack-rdo [bug 1796112]
Created runc tracking bugs for this issue:
Affects: fedora-all [bug 1796109]
---
Upstream commit for this issue:
https://github.com/opencontainers/runc/pull/2207/commits/3291d66b98445bd7f7d02eac7f2bca2ac2c56942
---
Jindrich can you get an update out for this?
Bugzilla
CVE-2019-19921 runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation [fedora-all]
bugzilla·2020-01-29·CVSS 7.0
CVE-2019-19921 [HIGH] CVE-2019-19921 runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation [fedora-all]
CVE-2019-19921 runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2019-19921 docker: runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation [fedora-all]
bugzilla·2020-01-29·CVSS 7.0
CVE-2019-19921 [HIGH] CVE-2019-19921 docker: runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation [fedora-all]
CVE-2019-19921 docker: runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit me
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00018.htmlhttps://access.redhat.com/errata/RHSA-2020:0688https://access.redhat.com/errata/RHSA-2020:0695https://github.com/opencontainers/runc/issues/2197https://github.com/opencontainers/runc/pull/2190https://github.com/opencontainers/runc/releaseshttps://lists.debian.org/debian-lts-announce/2023/03/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ANUGDBJ7NBUMSUFZUSKU3ZMQYZ2Z3STN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DHGVGGMKGZSJ7YO67TGGPFEHBYMS63VF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNB2UEDIIJCRQW4WJLZOPQJZXCVSXMLD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FYVE3GB4OG3BNT5DLQHYO4M5SXX33AQ5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I6BF24VCZRFTYBTT3T7HDZUOTKOTNPLZ/https://security-tracker.debian.org/tracker/CVE-2019-19921https://security.gentoo.org/glsa/202003-21https://usn.ubuntu.com/4297-1/http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00018.htmlhttps://access.redhat.com/errata/RHSA-2020:0688https://access.redhat.com/errata/RHSA-2020:0695https://github.com/opencontainers/runc/issues/2197https://github.com/opencontainers/runc/pull/2190https://github.com/opencontainers/runc/releaseshttps://lists.debian.org/debian-lts-announce/2023/03/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ANUGDBJ7NBUMSUFZUSKU3ZMQYZ2Z3STN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DHGVGGMKGZSJ7YO67TGGPFEHBYMS63VF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNB2UEDIIJCRQW4WJLZOPQJZXCVSXMLD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FYVE3GB4OG3BNT5DLQHYO4M5SXX33AQ5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I6BF24VCZRFTYBTT3T7HDZUOTKOTNPLZ/https://security-tracker.debian.org/tracker/CVE-2019-19921https://security.gentoo.org/glsa/202003-21https://usn.ubuntu.com/4297-1/
2020-02-12
Published