Lucene search

K
osvGoogleOSV:GO-2021-0070
HistoryApr 14, 2021 - 8:04 p.m.

Privilege escalation in github.com/opencontainers/runc

2021-04-1420:04:52
Google
osv.dev
12

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

GetExecUser in the github.com/opencontainers/runc/libcontainer/user package will improperly interpret numeric UIDs as usernames. If the method is used without verifying that usernames are formatted as expected, it may allow a user to gain unexpected privileges.

CPENameOperatorVersion
github.com/opencontainers/runclt0.1.0