RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-01-31T22:00:00
Updated: 2024-08-06T03:07:31.309Z
Reserved: 2016-12-15T00:00:00
Link: CVE-2016-9962
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-01-31T22:59:01.783
Modified: 2023-11-07T02:37:40.377
Link: CVE-2016-9962
Redhat