CVE-2024-21626

Aliases:GHSA-xr7r-f8xq-vfvvGO-2024-2491RHEA-2024:6124RHSA-2024:0645RHSA-2024:0662RHSA-2024:0666RHSA-2024:0670RHSA-2024:0684RHSA-2024:0717RHSA-2024:0752RHSA-2024:0755RHSA-2024:0756RHSA-2024:0757RHSA-2024:0758RHSA-2024:0759RHSA-2024:0760RHSA-2024:0764RHSA-2024:10149RHSA-2024:10520RHSA-2024:10525RHSA-2024:10841RHSA-2024:1270DEBIAN-CVE-2024-21626CGA-2266-gfwq-4qhgCGA-24pc-8mwq-r5x3CGA-266r-82qx-rp4rCGA-289p-c6c6-wxw8CGA-28rh-p78m-9xg4CGA-2cgp-49wg-72mfCGA-2h7v-wm65-74j2CGA-33qr-mcvw-5r2xCGA-3fcf-7wfp-qxmpCGA-3j8x-p9jv-rgfvCGA-3m9r-77vv-x2x5CGA-3mxj-pgfp-2w74CGA-3vxw-pqx2-xm3rCGA-46m7-6hfq-7frrCGA-4ff7-8g78-4ffrCGA-4j8v-87hx-px7xCGA-4q2w-w38g-88rgCGA-58jx-6934-p965CGA-5hj9-3r9c-c47hCGA-5r4m-pq7f-q93jCGA-5rhp-vf5x-xvx4CGA-5rm6-8wxg-gw9hCGA-5v8r-jr5r-j833CGA-6277-w7jv-jvpcCGA-686j-crp5-cw5mCGA-68r2-9x8h-3mfqCGA-6f35-g87j-vwpgCGA-6hqg-rp4g-w5p4CGA-6phg-7c86-p8hcCGA-6vxr-vj6w-fvpvCGA-6x7g-79wh-r9mvCGA-7564-rwrp-pcpmCGA-78gc-27xv-hxm8CGA-7c8p-h3vj-5m2mCGA-7mwr-qj2g-hgrgCGA-7vgh-93hr-wccwCGA-88m5-6qph-rrv8CGA-8pqp-mp9g-mvh8CGA-8qcr-pj6f-x246CGA-8rvj-q853-qp55CGA-9224-g7w6-p9mxCGA-959x-cq9v-875pCGA-98vj-9p45-vf2vCGA-9c9j-96r5-q7wqCGA-9rqv-p2x4-hp2fCGA-c3fr-fvhh-24h7CGA-c4cm-m882-qgm8CGA-c4p7-r2h5-rfv8CGA-cwcc-j277-g286CGA-f2wx-gc3w-w3fpCGA-f97p-4hqv-mcxpCGA-f9r9-4c37-7cvxCGA-fgqh-7wp3-qjqhCGA-fhhx-4857-h9wwCGA-fw3w-wc66-j7hrCGA-fw73-6vq2-3x46CGA-g3x6-2fjj-3vcpCGA-g4rc-2vm2-hv84CGA-gh8f-6592-r6v9CGA-gj2p-qpvr-55m3CGA-gj6w-9c5w-6797CGA-gj9h-m242-j6gwCGA-h2cc-xqqf-2vvwCGA-h3f4-fpg2-286gCGA-h472-5rpf-6gm4CGA-h4hh-f6c6-88q7CGA-hhmc-8v2r-qv4rCGA-hmgc-g4xc-x5mcCGA-j5gj-hf85-rmhwCGA-j5hc-w5ch-2rhqCGA-j62p-rh9j-6v24CGA-jhh7-x5wh-43jhCGA-jhjx-jp7c-68chCGA-jjmp-93r6-274hCGA-jqp3-qmp5-x2jxCGA-jrg4-r66r-rm5xCGA-jwv7-9j53-rr83CGA-m2qc-4jwx-xm5cCGA-m559-ff6p-w9gvCGA-m5gv-qmhj-wg82CGA-m723-qjh2-3pgjCGA-m7ph-69v2-cf42CGA-m96h-354w-w3x8CGA-mmxr-6w63-qpxmCGA-mq68-47pf-v2m4CGA-mqjp-5fmc-8xpwCGA-mrgc-8cfv-rg5gCGA-p34p-w76f-g7p3CGA-p375-h9pw-4qmhCGA-p9jx-5qr6-wvq8CGA-pcxh-j7wr-5hgqCGA-pj26-hqvp-7gj3CGA-pjgc-7vxq-7358CGA-pjq5-5jq3-qmxwCGA-q2p7-5jvq-49c3CGA-q3w4-xwqg-475cCGA-q4pg-grc3-8q34CGA-q6rc-x469-r2x8CGA-q9gg-qm2w-722qCGA-qmgc-gj66-g3qcCGA-qq5r-4v25-4c56CGA-qw34-mmxq-pmqhCGA-qx75-82w6-h42hCGA-r965-g7fj-786mCGA-rqm4-gj5h-86rqCGA-rv4f-q37f-x94gCGA-rvx6-x43w-hr8wCGA-rx6v-9pwj-q723CGA-v7wc-h7wj-rxwmCGA-vcrp-px2q-5gjqCGA-vfmf-5wpx-w4m3CGA-vg66-w48x-g62fCGA-vpc2-rjj6-jx65CGA-w9mx-9fw7-pq34CGA-w9pp-x6rp-68xjCGA-wh6h-gwg7-wg3xCGA-wjjw-7x2m-w5pqCGA-wmvc-jq5r-8p7rCGA-xcmv-hwm6-cmccCGA-xfj7-9vj9-22gvCGA-xfp5-2fj6-qr9cCGA-xj2h-hfq5-69gfCGA-xrc8-jh4j-8r5fCGA-xv6m-24gv-46vxCGA-xvw6-rw5j-74pjCGA-xw8w-6ggr-rjwr
Modified
Published: 31 Jan 2024, 21:31
Last modified:17 Sept 2026, 12:04

Vulnerability Summary

Overall Risk (default)
medium
48/100
CVSS Score
8.6 HIGH
v3.1 (cve.org)
EPSS Score
18.09% MEDIUM
18% probability +13.53%
KEV
Not listed
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected

Timeline

31 Jan 2024, 21:31
Published
Vulnerability first disclosed
17 Sept 2026, 12:04
Last Modified
Vulnerability information updated

Description

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

CVSS Metrics

  • v3.1HIGHScore: 8.6CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 18.09% Percentile: 97%

Techniques & Countermeasures

  • CWE-403Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')

    A process does not close sensitive file descriptors before invoking a child process, which allows the child to perform unauthorized I/O operations using those descriptors.

  • CWE-668Exposure of Resource to Wrong Sphere

    The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • chainguardbuildkitd

    < 0.12.5-r1

  • chainguardcadvisor

    < 0.48.1-r4

  • chainguardctop

    < 0.7.7-r13

  • chainguarddocker

    < 25.0.2-r0

  • chainguarddocker-config-mirror-gcr

    < 25.0.2-r0

  • chainguarddocker-dind

    < 25.0.2-r0

  • chainguarddocker-init

    < 25.0.2-r0

  • chainguarddocker-oci-entrypoint

    < 25.0.2-r0

  • chainguarddockerd

    < 25.0.2-r0

  • chainguarddockerd-oci-entrypoint

    < 25.0.2-r0

  • chainguarddockerd-service

    < 25.0.2-r0

  • chainguardgrype

    < 0.74.4-r1

  • chainguardk3d

    < 5.6.0-r6

  • chainguardk3d-proxy

    < 5.6.0-r6

  • chainguardk3d-tools

    < 5.6.0-r6

  • chainguardk3s

    < 1.29.0-r1

  • chainguardk3s-multicall

    < 1.29.0-r1

  • chainguardk3s-static

    < 1.29.0-r1

  • chainguardk9s

    < 0.31.8-r0

  • chainguardkaniko

    < 1.20.1-r0

  • chainguardkaniko-compat

    < 1.20.1-r0

  • chainguardkaniko-warmer

    < 1.20.1-r0

  • chainguardkaniko-warmer-compat

    < 1.20.1-r0

  • chainguardkots

    < 1.107.0-r1

  • chainguardkots-compat

    < 1.107.0-r1

  • chainguardkots-symlink-compat

    < 1.107.0-r1

  • chainguardkubectl-1.25

    all

  • chainguardkubectl-1.25-default

    all

  • chainguardkubectl-1.26

    all

  • chainguardkubectl-1.26-default

    all

  • chainguardkubectl-1.27

    all

  • chainguardkubectl-1.27-default

    all | < 1.27.11-r1

  • chainguardkubectl-1.28

    all | < 1.28.9-r0

  • chainguardkubectl-1.28-default

    < 1.28.9-r0 | all | < 1.28.7-r1

  • chainguardkubectl-1.29

    < 1.29.3-r1

  • chainguardkubectl-1.29-default

    < 1.29.3-r1

  • chainguardkubectl-bash-completion-1.25

    all

  • chainguardkubectl-bash-completion-1.26

    all

  • chainguardkubectl-bash-completion-1.27

    all

  • chainguardkubectl-bash-completion-1.28

    all | < 1.28.9-r0

  • chainguardkubectl-bash-completion-1.29

    < 1.29.3-r1

  • chainguardkubescape

    < 3.0.3-r7

  • chainguardnerdctl

    < 1.7.3-r0

  • chainguardnewrelic-infrastructure-agent

    < 1.48.4-r1

  • chainguardpodman

    < 5.2.2-r1

  • chainguardpodman-doc

    < 5.2.2-r1

  • chainguardrunc

    < 1.1.12-r0

  • chainguardskaffold

    < 2.11.0-r0

  • chainguardskopeo

    < 1.14.2-r1

  • chainguardsyft

    < 0.104.0-r0

Showing first 50 affected entries in server-rendered view.

References (80)