x/vulndb: potential Go vuln in github.com/opencontainers/runc: CVE-2023-28642 #1683
Labels
excluded: EFFECTIVELY_PRIVATE
This vulnerability exists in a package can be imported, but isn't meant to be outside that module.
CVE-2023-28642 references github.com/opencontainers/runc, which may be a Go module.
Description:
runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when
/proc
inside the container is symlinked with a specific mount configuration. This issue has been fixed in runc version 1.1.5, by prohibiting symlinked/proc
. See PR #3785 for details. users are advised to upgrade. Users unable to upgrade should avoid using an untrusted container image.References:
Cross references:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: