runC: Container breakout — GLSA 202107-26

A vulnerability has been found in runC which could result in privilege escalation.

Affected packages

app-emulation/runc on all architectures
Affected versions < 1.0.0_rc95
Unaffected versions >= 1.0.0_rc95

Background

runC is a CLI tool for spawning and running containers according to the OCI specification.

Description

A vulnerability in runC could allow an attacker to achieve privilege escalation if specific mount configuration prerequisites are satisfied.

Impact

An attacker may be able to escalation privileges to gain access to the host system.

Workaround

There is no known workaround at this time.

Resolution

All runC users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-emulation/runc-1.0.0_rc95"
 

References

Release date
July 10, 2021

Latest revision
July 10, 2021: 1

Severity
low

Exploitable
remote

Bugzilla entries