HomeSecurityRunC: Vulnerabilities allow attackers access

RunC: Vulnerabilities allow attackers access

Several flaws were revealed in the runC command line, which can be exploited by malicious actors to escape the boundaries of the container and carry out attacks thereafter.

See also: Cisco Unity Connection: Critical vulnerability grants root privileges

RunC

The vulnerabilities, tracked as CVE-2024-21626, CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653, have been collectively named Leaky Vessels by cybersecurity firm Snyk. Multiple security vulnerabilities have been disclosed in the runC command-line tool, which could be exploited by malicious users to escape the container environment and launch attacks.

runC is a tool for launching and running containerized applications on Linux. It was originally developed as part of Docker and later isolated as a separate open source library in 2015.

Below is a brief description for each vulnerability:

  • CVE-2024-21626 (CVSS score: 8.6) – runC process.cwd and leaked fds container breakout
  • CVE-2024-23651 (CVSS score: 8.7) – Build-time race condition container breakout
  • CVE-2024-23652 (CVSS score: 10.0) – Buildkit Build-time Container Teardown Arbitrary Delete
  • CVE-2024-23653 (CVSS score: 9.8) – GRPC SecurityMode privilege check: Build-time container breakout

The most serious of the flaws is CVE-2024-21626, which can lead to container escape based on the `WORKDIR`.

See also: Vulnerability in glibc allows root access on Linux distributions

There is no evidence that any of the newly discovered vulnerabilities have been exploited to date. However, these concerns have been addressed in runC version 1.1.12 released today, following the responsible disclosure in November 2023.

According to an independent advisory, it was shown that Docker vulnerabilities can only be exploited if the user actively interacts with malicious content by incorporating it into the build process or by running a container from a fake image.

vulnerabilities

Both Amazon Web Services (AWS) and Google Cloud have issued alerts, urging customers to take appropriate action as needed.

In February 2019, runC developers discovered another serious vulnerability (CVE-2019-5736, CVSS score: 8.6) that could be exploited by an attacker to escape the container and gain access to the host computer.

Security vulnerabilities in the cloud and containers sector continue to pose an attack risk as organizations grant excessive permissions and administrative privileges to accounts upon initial setup, leaving behind opportunities for misconfiguration and privilege escalation for attackers.

See also: Trend Micro fixes critical zero-day vulnerability in Apex One

What are the best practices for protecting digital assets?

One of the most effective ways to protect your digital assets is to use strong passwords. This means that passwords should be long, complex, and unique, including a mix of letters, numbers, and symbols.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, keeping your software and applications up to date is crucial. Updates often include security patches that can protect your digital assets from the latest threats.

Using antivirus and antimalware software is also important. These tools can detect and remove any malware that may threaten your digital assets.

Using multi-factor authentication (MFA) is another effective way to protect your digital assets. MFA requires two or more verification methods to confirm your identity before allowing you access to your data.

Finally, it is important to regularly back up your digital assets. This can help you restore data in the event that it is lost or damaged due to a cybercriminal attack.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS