Junglewise Threat Intelligence

CVE-2024-21626: opencontainers runc container breakout via leaked file descriptors

CVE-2024-21626 · Severity: high · CVSS 8.6 · Published 2024-01-31

Technologies: Open Container Initiative Runc, github.com/opencontainers/runc (Go). Vendors: Open Container Initiative, Go.

Executive brief

runc, a widely used tool for spawning and running containers, is vulnerable to a container breakout. An attacker can exploit leaked file descriptors to gain access to the host's filesystem or overwrite host binaries. This could allow a malicious container to take full control of the underlying server, potentially leading to data theft or service disruption.

Technical details

runc 1.1.11 and earlier contains multiple vulnerabilities related to internal file descriptor leaks (specifically /sys/fs/cgroup) and a lack of verification that the working directory remains within the container's mount namespace after chdir(2). An attacker can exploit this by setting a malicious process.cwd (e.g., /proc/self/fd/7/) or using symlinks to trick runc into executing processes with a working directory on the host. Furthermore, by using magic-links like /proc/self/fd/7/../../../bin/bash as process.args, an attacker can execute and subsequently overwrite host binaries. These issues are addressed in runc 1.1.12 by validating the working directory via getcwd() and ensuring all internal file descriptors are closed or marked O_CLOEXEC before execution.

Affected products

  • opencontainers runc >= 1.0.0-rc93, <= 1.1.11

Timeline

  • 2024-01-31: disclosed
  • 2024-01-31: advisory
  • 2024-01-31: patched

References

Related threats