cbcvebase.
CVE-2023-27561
published 2023-03-03

CVE-2023-27561: runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must…

high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianrunc< runc 1.1.5+ds1-1 (bookworm)runc 1.1.5+ds1-1 (bookworm)
github.comopencontainers_runc>= 0 < 1.1.51.1.5
github.comopencontainers_runc>= 1.0.0-rc95 < 1.1.51.1.5
linuxfoundationrunc< 1.1.51.1.5
linuxfoundationrunc>= 0 < 1.0.0~rc93+ds1-5+deb11u51.0.0~rc93+ds1-5+deb11u5
linuxfoundationrunc>= 0 < 1.1.5+ds1-11.1.5+ds1-1
linuxfoundationrunc>= 0 < 1.1.5+ds1-11.1.5+ds1-1
linuxfoundationrunc>= 0 < 1.1.5+ds1-11.1.5+ds1-1
linuxfoundationrunc>= 0 < 1.1.4-0ubuntu1~18.04.21.1.4-0ubuntu1~18.04.2
linuxfoundationrunc>= 0 < 1.1.4-0ubuntu1~20.04.31.1.4-0ubuntu1~20.04.3
linuxfoundationrunc>= 0 < 1.1.4-0ubuntu1~22.04.31.1.4-0ubuntu1~22.04.3
linuxfoundationrunc>= 0 < 1.0.0~rc7+git20190403.029124da-0ubuntu1~16.04.4+esm41.0.0~rc7+git20190403.029124da-0ubuntu1~16.04.4+esm4
msrccbl2_moby-runc_1.1.5-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_moby-runc_1.1.5+azure-1_on_cbl_mariner_1.0
redhatenterprise_linux
redhatenterprise_linux
redhatopenshift_container_platform

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa7.0HIGH
osv7.0HIGH