Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39582
HistoryMar 08, 2023 - 2:33 a.m.

Sandbox Restrictions Bypass

2023-03-0802:33:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
sandbox restrictions bypass
privilege escalation
vulnerability
rootfs validation
custom volume mount
custom images
cve-2019-19921 regression

0.001 Low

EPSS

Percentile

19.2%

github.com/opencontainers/runc is vulnerable to Privilege Escalation. The vulnerability exists because the prepareRootfs function in rootfs_linux.go does not properly validate the root config, which allows an attacker to obtain the host root when spawning two containers with custom volume-mount configurations and while running custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

References