Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8 MGASA-2021-0553 Moderate: runc Overflow Threat

mageia
Calendar Grey December 10, 2021
Dist Mageia Esm H88
Tackling the overflow problem in runc by implementing critical security patches ensures the safeguarding of Mageia 8 container setups.
It was discovered that there was an overflow issue in runc, the runtime for the Open Container Project, often used with Docker

Summary

It was discovered that there was an overflow issue in runc, the runtime for the Open Container Project, often used with Docker. The Netlink 'bytemsg' length field could have allowed an attacker to override Netlink-based container configurations. This vulnerability required the attacker to have some control over the configuration of the container, but would have allowed the attacker to bypass the namespace restrictions of the container by simply adding their own Netlink payload which disables all namespaces. (CVE-2021-43784)

References

- https://bugs.mageia.org/show_bug.cgi?id=29738

- https://lists.debian.org/debian-lts-announce/2021/12/msg00005.html

- https://www.cve.org/CVERecord?id=CVE-2021-43784

Resolution

SRPMS

- 8/core/opencontainers-runc-1.0.3-1.mga8

Publication date: 10 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0553.html
Type: security
CVE: CVE-2021-43784

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here