Vulnerability Report: GO-2022-0274
- CVE-2021-43784, GHSA-v95c-p5hm-xq8f
- Affects: github.com/opencontainers/runc
- Published: Jul 15, 2022
- Modified: May 20, 2024
An attacker with partial control over the bind mount sources of a new container can bypass namespace restrictions.
Affected Packages
-
PathGo VersionsSymbols
-
from v1.0.1-0.20211012131345-9c444070ec7b before v1.1.0
Aliases
References
- https://github.com/opencontainers/runc/commit/f50369af4b571e358f20b139eea52d612eb55eed
- https://github.com/opencontainers/runc/commit/dde509df4e28cec33b3c99c6cda3d4fd5beafc77
- https://bugs.chromium.org/p/project-zero/issues/detail?id=2241
- https://vuln.go.dev/ID/GO-2022-0274.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.