Lucene search

K
osvGoogleOSV:GHSA-FGV8-VJ5C-2PPQ
HistoryFeb 22, 2022 - 3:38 p.m.

Incorrect Authorization in runc

2022-02-2215:38:08
Google
osv.dev
22

0.003 Low

EPSS

Percentile

70.7%

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

References