Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
Vulnerability Description
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string which allow an image with /dev as a symlink to trick runc into deleting files called ptmx on the host or creating a hardcoded set of symlinks with specific names and targets in an arbitrary pre-existing host directory. This issue is not exploitable under Docker, because Docker creates a top-level read-only layer that masks any malicious /dev symlink present in the container image — unlike some other Linux container tooling, whose higher-level runtimes built on runc remain exposed to exploitation via a malicious image. This issue has been fixed in versions 1.3.6, 1.4.3 and 1.5.0.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Vulnerability Type
CWE-61
Vulnerability Title
opencontainers runc 后置链接漏洞
Vulnerability Description
opencontainers runc是opencontainers组织的一款容器运行时管理软件。 opencontainers runc存在后置链接漏洞,该漏洞源于在设置容器根文件系统时,setupPtmx和setupDevSymlinks函数通过filepath.Join字符串调用os.Remove和os.Symlink,允许含有/dev为符号链接的镜像欺骗runc删除主机上名为ptmx的文件,或在任意预存在的主机目录中创建硬编码的特定名称和目标的符号链接。以下版本受到影响:1.3.6之前版本、1.4
CVSS Information
N/A
Vulnerability Type
N/A