CVE-2023-27561
Published
CVSS v3
7
HIGH
CVSS v2
N/A
Affected
1
PROJECT
Description
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
CLI tool for spawning and running containers according to the OCI specification