QID 159170

Date Published: 2021-05-10

QID 159170: Oracle Enterprise Linux Security Update for runc (ELSA-2021-9203)

Oracle Enterprise Linux has released a security update for runc bug to fix the vulnerabilities.

Affected Product:
Oracle Linux 7

This vulnerability could be exploited to gain complete access to sensitive information. Malicious users could also use this vulnerability to change all the contents or configuration on the system. Additionally this vulnerability can also be used to cause a complete denial of service and could render the resource completely unavailable.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    To resolve this issue, upgrade to the latest packages which contain a patch. Refer to Oracle Enterprise Linux advisory below for updates and patch information:

    ELSA-2021-9203.
    Vendor References

    CVEs related to QID 159170

    Software Advisories
    Advisory ID Software Component Link
    ELSA-2021-9203 Oracle Linux URL Logo linux.oracle.com/errata/ELSA-2021-9203.html