PT-2024-1467 · Unknown+12 · Kubernetes Containerd+12

·

CVE-2024-21626

·

Published

2023-11-07

·

Updated

2026-08-31

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions runc versions 1.0.0-rc93 through 1.1.11 containerd versions 1.4.7 through 1.6.27 containerd versions 1.7.0 through 1.7.12 Docker versions 20.10.8 through 24.0.8 Docker versions 24.0.9 through 25.0.2
Description An internal file descriptor leak in runc, a CLI tool for spawning and running containers on Linux according to the OCI specification, allows for multiple container breakouts. The issue occurs because a file descriptor remains open during the setcwd(2) operation, even when O CLOEXEC is used on all descriptors before executing container code. This allows a reference to be maintained within the container by configuring the working directory to a path resolved through that file descriptor.
Exploitation can occur in several ways:
  • A newly-spawned container process via runc exec can have a working directory in the host filesystem namespace, granting access to the host filesystem.
  • A malicious image can use runc run to gain access to the host filesystem.
  • Variants of these methods can be used to overwrite semi-arbitrary host binaries, leading to a complete container escape and arbitrary code execution outside the isolated environment.
Recommendations Update runc to version 1.1.12. Update containerd to version 1.6.28 or 1.7.13. Update Docker to version 24.0.9 or 25.0.2. As a temporary mitigation, close all unneeded file descriptors to prevent the leak from being exploited.

Exploit

Fix

RCE

Exposure of Resource to Wrong Sphere

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023_6380
ALSA-2024:0670
ALSA-2024:0748
ALSA-2024:0752
ALSA-2024_0670
ALSA-2024_0748
ALSA-2024_0752
ALSA-2024_1131
ALSA-2024_1149
ALSA-2024_2160
ALSA-2024_2180
ALSA-2024_2193
ALSA-2024_2239
ALSA-2024_2245
ALSA-2024_2272
ALSA-2025_16880
ALT-PU-2024-1729
ALT-PU-2024-1733
ALT-PU-2024-1740
ALT-PU-2024-1975
AZL-34060
AZL-34074
AZL-34075
AZL-34087
AZL-34642
AZL-34896
AZL-34905
AZL-35006
AZL-39606
AZL-43429
AZL-43789
AZL-44226
AZL-44340
BDU:2024-00973
CESA-2024_0748
CESA-2024_0752
CLEANSTART-2026-MW42038
CVE-2024-21626
DLA-3735-1
DSA-5615-1
ELSA-2024-0670
ELSA-2024-0748
ELSA-2024-0752
ELSA-2024-12148
ELSA-2024-17931
GHSA-XR7R-F8XQ-VFVV
GO-2024-2491
OESA-2024-1182
OPENSUSE-SU-2024:13644-1
OPENSUSE-SU-2024:13754-1
OPENSUSE-SU-2024:14059-1
OPENSUSE-SU-2024_0459-1
OPENSUSE-SU-2025:0074-1
RHSA-2024:0645
RHSA-2024:0662
RHSA-2024:0666
RHSA-2024:0670
RHSA-2024:0684
RHSA-2024:0717
RHSA-2024:0748
RHSA-2024:0752
RHSA-2024:0755
RHSA-2024:0756
RHSA-2024:0757
RHSA-2024:0758
RHSA-2024:0759
RHSA-2024:0760
RHSA-2024:0764
RHSA-2024:10149
RHSA-2024:10520
RHSA-2024:10525
RHSA-2024:10841
RHSA-2024:1270
RHSA-2024:4597
RHSA-2024_0670
RHSA-2024_0748
RHSA-2024_0752
RLSA-2024:0752
RLSA-2024_0748
RLSA-2024_0752
ROSA-SA-2024-2393
ROSA-SA-2025-2670
SUSE-SU-2024:0294-1
SUSE-SU-2024:0295-1
SUSE-SU-2024:0328-1
SUSE-SU-2024:0459-1
SUSE-SU-2024_0294-1
SUSE-SU-2024_0295-1
SUSE-SU-2024_0328-1
SUSE-SU-2024_0459-1
USN-6619-1

Affected Products

Alt Linux
Almalinux
Centos
Check Point Gaia
Docker
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Kubernetes Containerd
Runc