Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 0 articles for you...
210

runC Security Flaws: Critical Access Risks for Linux Environments

A series of severe security vulnerabilities have been discovered in the popular runC command line tool. These vulnerabilities, collectively known as Leaky Vessels, allow threat actors to break out of containers and gain unauthorized access to the host operating system. . We'll examine the implications of these flaws, raise critical questions, and discuss the impact on Linux admins, infosec professionals, internet security enthusiasts, and sysadmins. What Are These Vulnerabilities & How Do They Impact runC Users? The runC command line tool is widely used for running containers on Linux. runC was initially developed as part of Docker and later became an independent open-source library. The vulnerabilities recently found in runC, tracked as CVE-2024-21626 , CVE-2024-23651 , CVE-2024-23652 , and CVE-2024-23653 , have been labeled Leaky Vessels by cybersecurity researchers. The most severe vulnerability is CVE-2024-21626, which revolves around the "WORKDIR" command. According to researchers, this flaw can be exploited by running a malicious image or building a container image using a malicious Dockerfile. It is concerning that these container escapes can provide attackers with unauthorized access to the underlying host operating system, potentially compromising sensitive data and granting superuser privileges. The above vulnerabilities have been addressed in runC version 1.1.12, which was released recently. However, it is crucial for Linux admins, infosec professionals, and sysadmins to ensure that their container runtime environments, including Docker, Kubernetes vendors, and cloud container services, are updated to mitigate these risks. The implications of these runC vulnerabilities are significant and require the attention of security practitioners globally. Firstly, the widespread use of runC makes this a pervasive threat, potentially affecting countless containerized applications running on Linux. Considering the rise of containerization as a preferred deployment method, the impacton both businesses and personal users can be substantial. Furthermore, there is currently no evidence of these flaws being exploited in the wild. However, this raises the question of how many attackers are already aware of these vulnerabilities and have the ability to exploit them covertly. The delay between vulnerability disclosure and patch implementation could allow attackers to gain unauthorized access and exfiltrate critical data. This highlights the urgency for Linux admins and infosec professionals to update their container runtime environments regularly . However, the responsibility does not solely lie with them. Vendors providing container runtime environments, such as Docker and Kubernetes, as well as cloud container services, need to prioritize prompt updates and communicate the severity of these vulnerabilities to their users effectively. The long-term consequences of these runC vulnerabilities extend beyond immediate remediation. This serves as a reminder that security should be an ongoing process rather than a one-time action. It emphasizes the need for continuous monitoring , vulnerability scanning , and timely patch management, particularly in the context of open-source and Linux security. Our Final Thoughts on These "Leaky Vessels" Bugs The critical vulnerabilities in the runC command line tool present considerable risks to containerized applications and the security posture of organizations relying on Linux environments. The significance of the flaws and the need for urgent action must be emphasized. Security practitioners, Linux admins, and infosec professionals must prioritize installing updates across container runtime environments to mitigate the potential impact of these vulnerabilities. As the field of containerization continues to evolve, the integration of robust security measures becomes increasingly crucial. Be sure to subscribe to our weekly newsletters for updates on flaws like these impacting the security of your Linux systems. Stay safe out there,Linux users! . Discover critical security flaws in the runC utility that may allow container breaches, threatening the integrity of Linux systems and compromising user information.. runC Security Flaws, Container Escape Risks, Linux Security Updates. . Anthony Pell

Calendar 2 Feb 27, 2024 User Avatar Anthony Pell Security Vulnerabilities
210

Azure Service Fabric Critical Fix for Privilege Escalation Threat

Microsoft has fixed a container escape bug dubbed FabricScape in the Service Fabric (SF) application hosting platform that let threat actors escalate privileges to root, gain control of the host node, and compromise the entire SF Linux cluster. . Service Fabric is a platform for business-critical applications that hosts over 1 million apps, according to Microsoft data . It also powers many Microsoft products , including but not limited to Azure SQL Database, Azure Cosmos DB, Microsoft Intune, Azure Event Hubs, Azure IoT Hub, Dynamics 365, Skype for Business, Cortana, Microsoft Power BI, and multiple core Azure services. . An essential patch resolves a vulnerability allowing container escape within Microsoft's Azure Service Fabric, affecting Linux-based clusters.. Azure Service Fabric, container escape, privilege escalation, Linux cluster. . Brittany Day

Calendar 2 Jul 01, 2022 User Avatar Brittany Day Security Vulnerabilities
210

Linux Kernel High Severity Advisory: CVE-2022-0492 Container Escape Risk

Details have emerged about a now-patched high-severity vulnerability in the Linux kernel that could potentially be abused to escape a container in order to execute arbitrary commands on the container host. . The shortcoming resides in a Linux kernel feature called control groups , also referred to as cgroups version 1 (v1), which allows processes to be organized into hierarchical groups, thereby making it possible to limit and monitor the usage of resources such as CPU, memory, disk I/O, and network. Tracked as CVE-2022-0492 (CVSS score: 7.0), the issue concerns a case of privilege escalation in the cgroups v1 release_agent functionality, a script that's executed following the termination of any process in the cgroup. The link for this article located at The Hacker News is no longer available. . A high-severity kernel vulnerability, CVE-2023-XXXX, allows container escape and unauthorized command execution, urging users to apply security patches promptly.. Container Escape, Linux Kernel Security, Privilege Escalation. . Brittany Day

Calendar 2 Mar 08, 2022 User Avatar Brittany Day Security Vulnerabilities
212

Linux Kernel 5.x High Severity: CVE-2022-0185 Kubernetes Escape Threat

Hackers could exploit a Linux kernel bug to escape Kubernetes containers and access critical resources; however, the threat is minimized as any attacker needs to have the specific Linux capability CAP_SYS_ADMIN. . The high-severity Common Vulnerabilities and Exposures (CVE) 2022-0185 , first reported by security publication BleepingComputer, affects all Linux kernel versions from 5.1-rc1 to the latest releases (5.4.173, 5.10.93, 5.15.1). The public exploit code for the issue is expected to be released soon by Crusaders of Rust (CoR), the team which discovered the vulnerability, meaning all systems at risk from this issue should apply the patch as soon as possible. . A vulnerability in the Linux kernel facilitates the escape of Kubernetes containers, compromising vital resources. Implement necessary patches immediately for CVE-2022-0185.. Linux Kernel Exploit,Kubernetes Security,Container Vulnerability. . Brittany Day

Calendar 2 Feb 04, 2022 User Avatar Brittany Day Cloud Security
210

Docker: Critical Escape Bug Advisory - Update to Version 19.03.1

Are you a Docker customer? If so, you should upgrade to the latest version of Docker immediately. Security researchers have detailed a proof-of-concept (PoC) attack exploiting a critical vulnerability, which could lead to full container escape. Learn more: . The CVE-2019-14271 flaw was fixed in Docker version 19.03.1 , but if left unpatched could give an attacker full root code execution on the host. “The vulnerability can be exploited, provided that a container has been compromised by a previous attack (e.g. through any other vulnerability, leaked secrets, etc.), or when a user runs a malicious container image from an untrusted source (registry or other),” explained Palo Alto Networks senior security researcher, Yuval Avrahami. “If the user then executes the vulnerable cp command to copy files out of the compromised container, the attacker can escape and take full root control of the host and all other containers in it.” The link for this article located at Infosecurity is no longer available. . CVE-2021-22918 was addressed in Kubernetes 1.19.3, yet vulnerable installations could encounter significant risks.. Docker Escape Bug, Container Security, Critical Vulnerability, Docker Update, Root Access Risk. . Brittany Day

Calendar 2 Nov 20, 2019 User Avatar Brittany Day Security Vulnerabilities
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here