← Back to advisories & guidance
February 6, 2024
CERT-EU
Advisory
Summary
This vulnerability, tracked as CVE-2024-21626 with a CVSS score of 8.6, enables attackers to escape containers and potentially gain unauthorised access to the host operating system. The vulnerability CVE-2024-21626 arises from an internal file descriptor leak within runc, a core component for running containers according to the Open Container Initiative (OCI) standards. The vulnerability manifests through the improper handling of file descriptors and the WORKDIR directive in Dockerfiles, allowing a container process to maintain access to privileged host directory file descriptors. Attackers can exploit this by manipulating the container’s working directory to point to these file descriptors, gaining the ability to read from or write to the host filesystem. This vulnerability impacts systems running runc version 1.1.11 and earlier.
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
Extracted from the publication text. Each CVE links to its tracked detail page.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.