Vulnerability Report: GO-2021-0087
- CVE-2019-19921, GHSA-fh74-hm69-rqjw
- Affects: github.com/opencontainers/runc
- Published: Apr 14, 2021
- Modified: May 20, 2024
A race while mounting volumes allows a possible symlink-exchange attack, allowing a user whom can start multiple containers with custom volume mount configurations to escape the container.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.0.0-rc9.0.20200122160610-2fc03cc11c77
1 unexported affected symbols
- mountToRootfs
Aliases
References
- https://github.com/opencontainers/runc/pull/2207
- https://github.com/opencontainers/runc/commit/2fc03cc11c775b7a8b2e48d7ee447cb9bef32ad0
- https://github.com/opencontainers/runc/issues/2197
- https://vuln.go.dev/ID/GO-2021-0087.json
Credits
- Leopold Schabel
Feedback
See anything missing or incorrect?
Suggest an edit to this report.