Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
runc 安全漏洞
Vulnerability Description
runc是一款用于根据OCI规范生成和运行容器的CLI(命令行界面)工具。 runc 1.0.0-rc8及之前版本(使用在Docker 19.03.2-ce及之前版本和其他产品)中存在安全漏洞,该漏洞源于libcontainer/rootfs_linux.go文件没有正确检查挂载目标。攻击者可利用该漏洞绕过AppArmor限制。
CVSS Information
N/A
Vulnerability Type
N/A