发布时间: 2023年4月11日
修改时间: 2024年10月31日
runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. This issue has been fixed in runc version 1.1.5, by prohibiting symlinked `/proc`. See PR #3785 for details. users are advised to upgrade. Users unable to upgrade should avoid using an untrusted container image.
NVD | openEuler | |
---|---|---|
Confidentiality | High | Low |
Attack Vector | Local | Local |
CVSS评分 | 7.8 | 6.1 |
Attack Complexity | Low | Low |
Privileges Required | Low | None |
Scope | Unchanged | Changed |
Integrity | High | Low |
User Interaction | None | Required |
Availability | High | Low |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2023-1278 | runc security update | 2023年4月14日 |
KylinSec-SA-2023-1629 | runc security update | 2023年7月1日 |
KylinSec-SA-2023-1888 | runc security update | 2023年4月14日 |
KylinSec-SA-2023-2133 | runc security update | 2023年4月11日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | runc | Fixed |
KY3.4-5A | runc | Fixed |
KY3.5.1 | runc | Fixed |
KY3.5.2 | runc | Fixed |