QID 982011

QID 982011: Go (go) Security Update for github.com/opencontainers/runc (GHSA-c3xm-pvg7-gh7r)

Security update has been released for github.com/opencontainers/runc to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.5 severity.
  • CVSS V2 rated as High - 6 severity.
  • Solution
    This has been patched in runc 1.0.0-rc95, and users should upgrade as soon as
    possible. The patch itself can be found [here](https://github.com/opencontainers/runc/commit/0ca91f44f1664da834bc61115a849b56d22f595f).Workaround:
    There are no known workarounds for this issue.

    However, users who enforce running containers with more confined security
    profiles (such as reduced capabilities, not running code as root in the
    container, user namespaces, AppArmor/SELinux, and seccomp) will restrict what
    an attacker can do in the case of a container breakout -- we recommend users
    make use of strict security profiles if possible (most notably user namespaces
    -- which can massively restrict the impact a container breakout can have on the
    host system).
    Vendor References

    CVEs related to QID 982011

    Software Advisories
    Advisory ID Software Component Link
    GHSA-c3xm-pvg7-gh7r github.com/opencontainers/runc URL Logo github.com/advisories/GHSA-c3xm-pvg7-gh7r