Skip to content

Commit

Permalink
automatic module_metadata_base.json update
Browse files Browse the repository at this point in the history
  • Loading branch information
msjenkins-r7 committed Mar 18, 2024
1 parent bf0d81d commit 7c7fa36
Showing 1 changed file with 6 additions and 2 deletions.
8 changes: 6 additions & 2 deletions db/modules_metadata_base.json
Original file line number Diff line number Diff line change
Expand Up @@ -86498,12 +86498,16 @@
"type": "exploit",
"author": [
"h00die",
"SickMcNugget",
"jheysel-r7",
"Rory McNamara"
],
"description": "All versions of runc <=1.1.11, as used by containerization technologies such as Docker engine,\n and Kubernetes are vulnerable to an arbitrary file write.\n Due to a file descriptor leak it is possible to mount the host file system\n with the permissions of runc (typically root).\n\n Successfully tested on Ubuntu 22.04 with runc 1.1.7-0ubuntu1~22.04.1 using Docker build.",
"description": "All versions of runc <=1.1.11, as used by containerization technologies such as Docker engine,\n and Kubernetes are vulnerable to an arbitrary file write.\n Due to a file descriptor leak it is possible to mount the host file system\n with the permissions of runc (typically root).\n\n Successfully tested on Ubuntu 22.04 with runc 1.1.7-0ubuntu1~22.04.1 and runc 1.1.11 using Docker build.\n Also tested on Debian 12.4.0 with runc 1.1.11 using Docker build.",
"references": [
"URL-https://snyk.io/blog/cve-2024-21626-runc-process-cwd-container-breakout/",
"URL-https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv",
"URL-https://security-tracker.debian.org/tracker/CVE-2024-21626",
"URL-https://ubuntu.com/security/CVE-2024-21626",
"CVE-2024-21626"
],
"platform": "Linux",
Expand All @@ -86518,7 +86522,7 @@
"targets": [
"Auto"
],
"mod_time": "2024-02-02 16:27:02 +0000",
"mod_time": "2024-03-11 22:23:55 +0000",
"path": "/modules/exploits/linux/local/runc_cwd_priv_esc.rb",
"is_install_path": true,
"ref_name": "linux/local/runc_cwd_priv_esc",
Expand Down

0 comments on commit 7c7fa36

Please sign in to comment.