Vulnerability Report: GO-2021-0085
- CVE-2019-16884, GHSA-fgv8-vj5c-2ppq
- Affects: github.com/opencontainers/runc, github.com/opencontainers/selinux
- Published: Apr 14, 2021
- Modified: May 20, 2024
AppArmor restrictions may be bypassed due to improper validation of mount targets, allowing a malicious image to mount volumes over e.g. /proc.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.0.0-rc8.0.20190930145003-cad42f6e0932
-
before v1.0.0-rc8.0.20190930145003-cad42f6e0932
-
before v1.3.1-0.20190929122143-5215b1806f52
2 unexported affected symbols
- readCon
- writeCon
Aliases
References
- https://github.com/opencontainers/runc/pull/2130
- https://github.com/opencontainers/runc/commit/cad42f6e0932db0ce08c3a3d9e89e6063ec283e4
- https://github.com/opencontainers/selinux/commit/03b517dc4fd57245b1cf506e8ba7b817b6d309da
- https://github.com/opencontainers/runc/issues/2128
- https://vuln.go.dev/ID/GO-2021-0085.json
Credits
- Leopold Schabel
Feedback
See anything missing or incorrect?
Suggest an edit to this report.