Description
RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2523 | RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container. |
Github GHSA |
GHSA-gp4j-w3vj-7299 | Information Exposure in RunC |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T03:07:31.309Z
Reserved: 2016-12-15T00:00:00.000Z
Link: CVE-2016-9962
No data.
Status : Modified
Published: 2017-01-31T22:59:01.783
Modified: 2026-05-13T00:24:29.033
Link: CVE-2016-9962
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
EUVD
Github GHSA