Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22301
HistoryJan 16, 2020 - 5:48 a.m.

Sandbox Restrictions Bypass

2020-01-1605:48:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20

0.0005 Low

EPSS

Percentile

17.1%

github.com/opencontainers/runc is vulnerable to sandbox restrictions bypass. An attacker who controls the container image for two containers that share a volume will be able to mount arbitrary volumes in a race condition during container initialization via a symlink that is added to the rootfs. This vulnerability allows a malicious container to mount /proc to another location within the attacker’s control and perform unauthorized writes to system files.