MGASA-2021-0412

Source
https://advisories.mageia.org/MGASA-2021-0412.html
Import Source
https://advisories.mageia.org/MGASA-2021-0412.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0412
Related
Published
2021-08-27T15:29:51Z
Modified
2021-08-27T15:05:28Z
Summary
Updated opencontainers-runc packages fix security vulnerability
Details

runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition (CVE-2021-30465).

References
Credits

Affected packages

Mageia:8 / opencontainers-runc

Package

Name
opencontainers-runc
Purl
pkg:rpm/mageia/opencontainers-runc?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.2-1.mga8

Ecosystem specific

{
    "section": "core"
}