{"id":"GHSA-g5p6-327m-3fxx","aliases":[],"url":"https://o3.security/vulnerability/GHSA-g5p6-327m-3fxx","summary":"Talos Linux ships runc vulnerable to the escape to the host attack","details":"### Impact\n\nSnyk has discovered a vulnerability in all versions of runc <=1.1.11, as used by the Docker engine, along with other containerization technologies such as Kubernetes. Exploitation of this issue can result in container escape to the underlying host OS, either through executing a malicious image or building an image using a malicious Dockerfile or upstream image (i.e., when using FROM). This issue has been assigned the CVE-2024-21626.\n\n### Patches\n\n`runc` runtime was updated to 1.1.12 in Talos v1.5.6 and v1.6.4.\n\n### Workarounds\n\nInspect the workloads running on the cluster to make sure they are not trying to exploit the vulnerability.\n\n### References\n\n* [CVE-2024-21626](https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv)\n* [Vulnerability: runc process.cwd and leaked fds container breakout](https://snyk.io/blog/cve-2024-21626-runc-process-cwd-container-breakout/)\n","published":"2024-02-02T18:11:06Z","modified":"2024-02-02T18:11:06Z","cvss":{"score":8.6,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/siderolabs/talos","fixedVersion":"1.6.4"},{"ecosystem":"Go","name":"github.com/siderolabs/talos","fixedVersion":"1.5.6"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/siderolabs/talos/security/advisories/GHSA-g5p6-327m-3fxx"},{"type":"PACKAGE","url":"https://github.com/siderolabs/talos"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-02T18:11:06Z"}}