QID 379336

QID 379336: Docker and runc container breakout Vulnerability (Leaky Vessels) (GHSA-xr7r-f8xq-vfvv)

A Container Breakout Vulnerability (CVE-2024-21626) was discovered in multiple runc packages
Affected Package and Versions:
github.com/opencontainers/runc version greater than or equal to v1.0.0-rc93 and less than 1.1.12

QID Detection Logic:(Authenticated)
TBD

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Refer to security advisory GHSA-xr7r-f8xq-vfvvfor details pertaining to this.

    CVEs related to QID 379336

    Software Advisories
    Advisory ID Software Component Link
    GHSA-xr7r-f8xq-vfvv URL Logo github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv