Executive brief
runc, a widely used tool for spawning and running containers, is vulnerable to a container breakout. An attacker can exploit leaked file descriptors to gain access to the host's filesystem or overwrite host binaries. This could allow a malicious container to take full control of the underlying server, potentially leading to data theft or service disruption.
Technical details
runc 1.1.11 and earlier contains multiple vulnerabilities related to internal file descriptor leaks (specifically /sys/fs/cgroup) and a lack of verification that the working directory remains within the container's mount namespace after chdir(2). An attacker can exploit this by setting a malicious process.cwd (e.g., /proc/self/fd/7/) or using symlinks to trick runc into executing processes with a working directory on the host. Furthermore, by using magic-links like /proc/self/fd/7/../../../bin/bash as process.args, an attacker can execute and subsequently overwrite host binaries. These issues are addressed in runc 1.1.12 by validating the working directory via getcwd() and ensuring all internal file descriptors are closed or marked O_CLOEXEC before execution.
Affected products
- opencontainers runc >= 1.0.0-rc93, <= 1.1.11
Timeline
- 2024-01-31: disclosed
- 2024-01-31: advisory
- 2024-01-31: patched
References
- https://api.github.com/users/rmcnamara-snyk
- https://github.com/rmcnamara-snyk
- https://api.github.com/users/rmcnamara-snyk/gists%7B/gist_id%7D
- https://api.github.com/users/rmcnamara-snyk/repos
- https://avatars.githubusercontent.com/u/139076586?v=4
- https://api.github.com/users/rmcnamara-snyk/events%7B/privacy%7D