Lucene search

K
amazonAmazonALAS-2021-1540
HistoryOct 01, 2021 - 5:58 p.m.

Medium: containerd

2021-10-0117:58:00
alas.aws.amazon.com
23
containerd
unprivileged users
permissions
executable programs
cve-2021-41103
red hat
mitre
linux users
security

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

14.2%

Issue Overview:

A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as setuid), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files. (CVE-2021-41103)

Affected Packages:

containerd

Issue Correction:
Run yum update containerd to update your system.

New Packages:

src:  
ย ย ย  containerd-1.4.6-3.9.amzn1.src  
  
x86_64:  
ย ย ย  containerd-stress-1.4.6-3.9.amzn1.x86_64  
ย ย ย  containerd-debuginfo-1.4.6-3.9.amzn1.x86_64  
ย ย ย  containerd-1.4.6-3.9.amzn1.x86_64  

Additional References

Red Hat: CVE-2021-41103

Mitre: CVE-2021-41103

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

14.2%