Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

[馃惛 Frogbot] Update version of github.com/opencontainers/runc to 1.1.12 #2430

Conversation

github-actions[bot]
Copy link
Contributor

@github-actions github-actions bot commented Feb 2, 2024

馃毃 This automated pull request was created by Frogbot and fixes the below:

馃摝 Vulnerable Dependencies

鉁嶏笍 Summary

SEVERITY CONTEXTUAL ANALYSIS DIRECT DEPENDENCIES IMPACTED DEPENDENCY FIXED VERSIONS CVES

High
Undetermined github.com/containerd/containerd:v1.7.11
github.com/opencontainers/runc:v1.1.5
github.com/testcontainers/testcontainers-go:v0.23.0
github.com/opencontainers/runc v1.1.5 [1.1.12] CVE-2024-21626

馃敩 Research Details

Description:
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.


@eyalbe4 eyalbe4 added the safe to test Approve running integration tests on a pull request label Feb 2, 2024
@github-actions github-actions bot removed the safe to test Approve running integration tests on a pull request label Feb 2, 2024
@eyalbe4 eyalbe4 closed this Feb 2, 2024
@eyalbe4 eyalbe4 reopened this Feb 2, 2024
@eyalbe4 eyalbe4 merged commit ffcc770 into dev Feb 2, 2024
61 checks passed
@sverdlov93 sverdlov93 deleted the frogbot-github.com/opencontainers/runc-78b160ba77a868cd9bc75bb8b723f83c branch March 18, 2024 19:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants