Vulnerability in runc allowing access to the filesystem outside the container

A vulnerability (CVE-2021-30465) has been identified in the runc tool used for running isolated containers in Docker and Kubernetes, allowing access from the container to the host environment's main filesystem. Through manipulation of symbolic links, it is possible to prepare an innocuous-looking container configuration that will lead to bind-mounting an external filesystem inside the container. The issue has been fixed in runc version 1.0.0-rc95.

To exploit the vulnerability, an attacker must have the ability to run containers with additional mount points in their configuration (for example, the issue is reproducible in Kubernetes-based environments where users can launch their own containers). Due to a time window between the check and the usage of mount points on partitions shared with other containers, an attacker can exploit a race condition during the container launch to replace the directory used for mounting in the container with a symbolic link to an area outside the container's root filesystem.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster