Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2024-21626

CVE-2024-21626: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh8.6

    High [CVE-2024-21626] runc container breakout through process.cwd trickery and leaked fds

    CVE-2024-21626Source published Source updated

    runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue. While a user performs `O_CLOEXEC` all file…

    Affected products in this advisory
    • OCP-Tools-4.15-RHEL-8
    • Red Hat Enterprise Linux 7 Extras
    • Red Hat Enterprise Linux 8.2 Advanced Update Support
    • Red Hat Enterprise Linux 8.2 Telecommunications Update Service

    21 more entries in the full advisory.

    Source-reported affected versions
    • 1.1.11
    Source-reported fixed versions
    • jenkins-0:2.440.3.1718879390-3.el8
    • jenkins-2-plugins-0:4.15.1718879538-1.el8
    • runc-0:1.0.0-70.rc10.el7_9
    • docker-2:1.13.1-210.git7d71120.el7_9

    44 more entries in the full advisory.

    Mitigation guidance
    • Red Hat Enterprise Linux (RHEL) and OpenShift ships with SELinux in targeted enforcing mode, which prevents the container processes from accessing host content and mitigates this attack. Dockerfiles can be inspected on the 'RUN' and 'WORKDIR' directives to ensure that there are no escapes or malicious paths, which are an indication of compromise. Limiting access and only using trusted container images can help prevent unauthorized access and malicious attacks.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery