Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian 10: DLA-3735-1 Moderate: Runc Control Character And Breakout

debian lts
Calendar Grey February 19, 2024
Dist Debian Esm H88
Enhance your runc installations on Debian 10 to mitigate recent vulnerabilities related to control characters and risks of container escape.
runc is a command line client for running applications packaged according to the Open Container Format (OCF) and is a compliant implementation of the Open Container Project specifi...

Summary

CVE-2021-43784

A flaw has been detected that may lead to a possible length field
overflow, allowing user-controlled data to be parsed as control
characters.

CVE-2024-21626

A flaw has been detected which allows several container breakouts
due to internally leaked file descriptors. The patch includes fixes
and hardening measurements against these types of issues/attacks.

For Debian 10 buster, these problems have been fixed in version
1.0.0~rc6+dfsg1-3+deb10u3.

We recommend that you upgrade your runc packages.

For the detailed security status of runc please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/runc

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Package: runc
Version: 1.0.0~rc6+dfsg1-3+deb10u3
CVE ID: CVE-2021-43784 CVE-2024-21626
Debian Bug:

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here