Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1192051 * bsc#1214960 * bsc#1221050 * bsc#1230092 . # Security update for runc Announcement ID: SUSE-SU-2025:20046-1 Release Date: 2025-02-03T08:56:20Z Rating: important References: * bsc#1192051 * bsc#1214960 * bsc#1221050 * bsc#1230092 Cross-References: * CVE-2024-45310 CVSS scores: * CVE-2024-45310 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N * CVE-2024-45310 ( NVD ): 3.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability and has three fixes can now be installed. ## Description: This update for runc fixes the following issues: Update to runc v1.1.14. Upstream changelog is available from . * CVE-2024-45310: Fixed that runc can be tricked into creating empty files/directories on host ( bsc#1230092) Update to runc v1.1.13. Upstream changelog is available from . * Fixed a performance issue when running lots of containers, caused by systemd getting too many mount notifications. bsc#1214960 * Fixed -ENOSYS stub on ppc64le. bsc#1192051 bsc#1221050 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-62=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * runc-1.1.14-1.1 * runc-debuginfo-1.1.14-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-45310.html * https://bugzilla.suse.com/show_bug.cgi?id=1192051 * https://bugzilla.suse.com/show_bug.cgi?id=1214960 * https://bugzilla.suse.com/show_bug.cgi?id=1221050 * https://bugzilla.suse.com/show_bug.cgi?id=1230092 . A key update for runc addresses a critical problem found in SUSE Linux Micro 6.0, featuring performance improvements as part of the release.. SUSE Linux Micro 6.0,runc update,security advisory,performance fix. . Severity:Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-6188 http://linux.oracle.com/errata/ELSA-2024-6188.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: runc-1.1.12-4.el9_4.x86_64.rpm aarch64: runc-1.1.12-4.el9_4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//runc-1.1.12-4.el9_4.src.rpm Related CVEs: CVE-2024-24783 Description of changes: [4:1.1.12-4] - rebuild for CVE-2024-24783 - Resolves: RHEL-28439 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4762 http://linux.oracle.com/errata/ELSA-2024-4762.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: runc-1.1.12-3.el9_4.x86_64.rpm aarch64: runc-1.1.12-3.el9_4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//runc-1.1.12-3.el9_4.src.rpm Related CVEs: CVE-2024-1394 Description of changes: [4:1.1.12-3] - rebuild for CVE-2024-1394 - Resolves: RHEL-24320 _______________________________________________ El-errata mailing list
An update for runc is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: runc security update Advisory ID: RHSA-2022:8090-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:8090 Issue date: 2022-11-15 CVE Names: CVE-2022-29162 ==================================================================== 1. Summary: An update for runc is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime. Security Fix(es): * runc: incorrect handling of inheritable capabilities (CVE-2022-29162) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2086398- CVE-2022-29162 runc: incorrect handling of inheritable capabilities 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: runc-1.1.4-1.el9.src.rpm aarch64: runc-1.1.4-1.el9.aarch64.rpm runc-debuginfo-1.1.4-1.el9.aarch64.rpm runc-debugsource-1.1.4-1.el9.aarch64.rpm ppc64le: runc-1.1.4-1.el9.ppc64le.rpm runc-debuginfo-1.1.4-1.el9.ppc64le.rpm runc-debugsource-1.1.4-1.el9.ppc64le.rpm s390x: runc-1.1.4-1.el9.s390x.rpm runc-debuginfo-1.1.4-1.el9.s390x.rpm runc-debugsource-1.1.4-1.el9.s390x.rpm x86_64: runc-1.1.4-1.el9.x86_64.rpm runc-debuginfo-1.1.4-1.el9.x86_64.rpm runc-debugsource-1.1.4-1.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-29162 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.1_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY3PhJ9zjgjWX9erEAQglkQ/+NMfaKI3svFA8CoZJjJxelGD7l5Q1fw+r 5rNT54DLvkHMqsx63bIs07+jMXmbzUQgCBUub8yWI7pkTdGnq9KsRvsElLwnOWAN elSl2ReDtUmynMubZrlWYZ93RdkOXAfWlzV4MYW7GnCu6TGokkdC/a0VBEOh/h4C RtIiXsvDI5frm9XYIPAMicI8FUR56ONR1Cob3Z2Pe9i63dAs4WXxVm/Cv11WyzQf +sqWACstPa87iY6NAak+8Kbw4nCEmGxRQR9z9vfQEUxG0y9DxExMkusKTm1Gx2SS lQ4YLcpkDtIpcoebcNMgR2G79+JEgezIF2rFV7euqX2hYPnhlHJTN5R9vnNIwLwL KyuLiRrRn9dIpXnUIhDqknOZmu8GnUIBmEYf5ibU2IdLCI5cC5U93QIN8NnW/0Jf SGlrtnc+pgT4/Pnrrh40odxerL8GwxFX0qPg0Jqta5wp3JuO3E7pXWZMNUBd5Npu mYmX3Vncsz34mNi83fDtFzgwh24BB9NuOk5X2M392Yrn6I0yAO+nxGouakeSFNdm TC072mzT/7Di1Q/Tkz7/oh3C1Xj1ub/YIJDBYcVyHQ3HNcR2nHJC2OhQMOqgLFEc Ie0qLhk33CcbWh5JcNi8+zAQBLKT5E/Ii0o0Wp9KvfWkkW+HEoAFHqsjhl/lql6s V8IOomEs/qU=KNI1 -----END PGP SIGNATURE----- -- RHSA-announce mailinglist
An update for runc is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: runc security update Advisory ID: RHSA-2021:2145-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2021:2145 Issue date: 2021-05-31 CVE Names: CVE-2021-30465 ==================================================================== 1. Summary: An update for runc is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux 7 Extras - ppc64le, s390x, x86_64 3. Description: The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime. Security Fix(es): * runc: vulnerable to symlink exchange attack (CVE-2021-30465) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1954736 - CVE-2021-30465 runc: vulnerable to symlink exchange attack 6. Package List: Red Hat Enterprise Linux 7Extras: Source: runc-1.0.0-69.rc10.el7_9.src.rpm ppc64le: runc-1.0.0-69.rc10.el7_9.ppc64le.rpm runc-debuginfo-1.0.0-69.rc10.el7_9.ppc64le.rpm s390x: runc-1.0.0-69.rc10.el7_9.s390x.rpm runc-debuginfo-1.0.0-69.rc10.el7_9.s390x.rpm x86_64: runc-1.0.0-69.rc10.el7_9.x86_64.rpm runc-debuginfo-1.0.0-69.rc10.el7_9.x86_64.rpm Red Hat Enterprise Linux 7 Extras: Source: runc-1.0.0-69.rc10.el7_9.src.rpm x86_64: runc-1.0.0-69.rc10.el7_9.x86_64.rpm runc-debuginfo-1.0.0-69.rc10.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-30465 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/security/vulnerabilities/RHSB-2021-004 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYLSWotzjgjWX9erEAQjOTBAAp/rIma//RTxEV1kW9fqh4V+qShGxMHPE 5V5UMNjCwI/kGoj57q39DmE3vgsfovfWwefpQ6ogj/wBWWap4p+etF+4LaaaJuUC FAV7AT1Xiyg1sNCA9uQ7KXEpjx92Bsye6KaThkG+RN0aMGPD2Vs90zGwCfSGGp9K 6Gb+GjSqiYBtYnIl/sUnZnUMKTPQJQPdJDYtyQTb+hulVW0Kw411vecJcM1i5nHm s5C6yqO4tXGh1D3f2xIjIpaCNERopeRrLDkhfAMhun+wfO40XlerTrbVCLgw9Igv 5D8Ebz+RVpSPGQwNCyWbsOZOLWjdTtiaitDnM4g57uglPXvL1ICQ0zy3y8jHhQWR IW3Ws/iQ8NmSU7lQCx9QO3DYb6eCdZvR3Wp/GPiGDTfO3kaKRWAfTwJKTc4EiYwu pU73Vhfy90MVYH1ZmWiSQRNs7kAQgELdoYdG2zhT8kcOQzlZJ+5BpLkRxAt2LhC2 AbRoXVPg37xXLSGzDoNDWpowxGz5JWDNBwvgUd9HlL/lqqhIbmi7Fwq1T7R68FjC zwUyyiOCDZtXDWACjgzAOV8wsmO7UkPmRbjlTIMxQYsZd9qrf+qjilCoqNCLGE++ VI7/oOW+aciDxSgX69ZYxiA6BXN+xC54QXgoNDp0Y6zrbXmisSMcgxYD27hrXMed dUJUk44amfk=C56E -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.