跳转到帖子

Alma Linux: CVE-2023-27561: Moderate: container-tools:4.0 security and bug fix update (Multiple Advisories)

recommended_posts

发布于
  • Members

Alma Linux: CVE-2023-27561: Moderate: container-tools:4.0 security and bug fix update (Multiple Advisories)

Severity
7
CVSS
(AV:L/AC:M/Au:S/C:C/I:C/A:C)
Published
03/03/2023
Created
11/17/2023
Added
11/16/2023
Modified
01/28/2025

Description

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

Solution(s)

  • alma-upgrade-aardvark-dns
  • alma-upgrade-buildah
  • alma-upgrade-buildah-tests
  • alma-upgrade-cockpit-podman
  • alma-upgrade-conmon
  • alma-upgrade-container-selinux
  • alma-upgrade-containernetworking-plugins
  • alma-upgrade-containers-common
  • alma-upgrade-crit
  • alma-upgrade-criu
  • alma-upgrade-criu-devel
  • alma-upgrade-criu-libs
  • alma-upgrade-crun
  • alma-upgrade-fuse-overlayfs
  • alma-upgrade-libslirp
  • alma-upgrade-libslirp-devel
  • alma-upgrade-netavark
  • alma-upgrade-oci-seccomp-bpf-hook
  • alma-upgrade-podman
  • alma-upgrade-podman-catatonit
  • alma-upgrade-podman-docker
  • alma-upgrade-podman-gvproxy
  • alma-upgrade-podman-plugins
  • alma-upgrade-podman-remote
  • alma-upgrade-podman-tests
  • alma-upgrade-python3-criu
  • alma-upgrade-python3-podman
  • alma-upgrade-runc
  • alma-upgrade-skopeo
  • alma-upgrade-skopeo-tests
  • alma-upgrade-slirp4netns
  • alma-upgrade-toolbox
  • alma-upgrade-toolbox-tests
  • alma-upgrade-udica

References

  • https://attackerkb.com/topics/cve-2023-27561
  • CVE - 2023-27561
  • https://errata.almalinux.org/8/ALSA-2023-6938.html
  • https://errata.almalinux.org/8/ALSA-2023-6939.html
  • https://errata.almalinux.org/9/ALSA-2023-6380.html
  • 查看数 710
  • 已创建
  • 最后回复