All errata/sisyphus/ALT-PU-2020-1252-2
ALT-PU-2020-1252-2

Package update runc in branch sisyphus

Version1.0.0-alt12.rc10
Published2026-02-04
Max severityHIGH
Severity:

Closed issues (2)

CVE-2019-19921
HIGH7.0

runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)

Published: 2020-02-12Modified: 2024-11-21
CVSS 2.0MEDIUM 4.4
CVSS:2.0/AV:L/AC:M/Au:N/C:P/I:P/A:P
CVSS 3.xHIGH 7.0
CVSS:3.x/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
References
GHSA-fh74-hm69-rqjw
MEDIUM5.9

opencontainers runc contains procfs race condition with a shared volume mount

Published: 2021-05-27Modified: 2024-05-31
CVSS 3.xMEDIUM 5.9
CVSS:3.x/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:U