CVE Tools
Home/Vulnerability/CVE-2024-21626

CVE-2024-21626

runc container breakout through process.cwd trickery and leaked fds

Published: Jan 31, 2024Updated: Nov 21, 2024 Sources: CVE List NVD GHSA BDU
8.6CVSS
HIGH

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

EPSS Score
5.1%
Top 10.0%
CISA KEV
Not in KEV
Exploits
1 Known
Remediation
Patch Available

CVSS Vector Breakdown

AV:LAC:LPR:NUI:RS:CC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Red Hat Enterprise Linux
Red Hat Inc.
OpenShift Container Platform
Red Hat Inc.
Ubuntu
Canonical Ltd.
Debian GNU/Linux
Сообщество свободного программного обеспечения
РЕД ОС
ООО «Ред Софт»
and 11 more affected products View all →

Exploitability

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

and 25 more references View all →

Timeline

Published
Jan 31, 2024
Last Updated
Nov 21, 2024
2

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2024-21626 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
AI-powered analysis
Plain-language impact assessment and exploitation scenario
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows