Incorrect default permissions in containerd - CVE-2021-41103
Published: October 4, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for container root directories and some plugins. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host can discover, read, and modify those files.
Affected software
DB2 Data Management Console
DB2 Data Management Console on CPD
DB2 on Cloud Pak for Data
Storage Ceph
IBM Cloud Pak for Security
Dell Secure Connect Gateway
Red Hat OpenStack
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE MicroOS
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
openEuler
Fedora
containerd (Debian package)
runc
runc-debuginfo
containerd
containerd (Ubuntu package)
app-containers/containerd
moby-engine
docker-debuginfo
docker
docker-fish-completion
docker-bash-completion
QRadar Suite
IBM Edge Application Manager
SCALANCE LPE9403
Cloud Pak for Data
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
How to mitigate CVE-2021-41103
containerd (Debian package) - update to 1.4.5~ds1-2+deb11u1
QRadar Suite - update to 1.10.19.0
DB2 Data Management Console - update to 3.1.13.1
DB2 Data Management Console on CPD - update to 4.7.2
Dell Secure Connect Gateway - update to 5.12.00.10
runc - addressed in versions 1.0.2-16.14.1, 1.0.2-23.1
runc-debuginfo - addressed in versions 1.0.2-16.14.1, 1.0.2-23.1
containerd - update to 1.2.0-201
containerd - addressed in versions 1.4.11-16.45.1, 1.4.11-56.1, 1.4.12-16.49.1, 1.4.12-60.1
containerd (Ubuntu package) - addressed in versions 1.5.2-0ubuntu1~18.04.3, 1.5.2-0ubuntu1~20.04.3, 1.5.2-0ubuntu1~21.04.3
containerd - addressed in versions 1.5.7-1.fc34, 1.5.7-1.fc35, 1.5.7-1.fc36
app-containers/containerd - update to 1.6.14
SCALANCE LPE9403 - update to 2.0
DB2 on Cloud Pak for Data - update to 4.8.4
Cloud Pak for Data - update to 4.8.5
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Storage Ceph - update to 7.1
Red Hat OpenStack - update to 16.2.z
moby-engine - addressed in versions 20.10.9-1.fc34, 20.10.9-1.fc35
docker-debuginfo - addressed in versions 20.10.12_ce-98.75.1, 20.10.12_ce-159.1
docker - addressed in versions 20.10.12_ce-98.75.1, 20.10.12_ce-159.1
docker-fish-completion - update to 20.10.12_ce-159.1
docker-bash-completion - update to 20.10.12_ce-159.1
External References
Related Security Bulletins
- Privilege escalation in containerd
- Amazon Linux AMI update for containerd
- Debian update for containerd
- Multiple vulnerabilities in Siemens SCALANCE LPE9403
- SUSE update for containerd, docker, runc
- SUSE update for containerd, docker, runc
- Ubuntu update for containerd
- Multiple vulnerabilities in Red Hat OpenStack 16.2
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.2
- SUSE update for containerd, docker
- SUSE update for containerd, docker
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- Gentoo update for containerd
- Multiple vulnerabilities in IBM QRadar Suite Software
- openEuler update for containerd
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in IBM Cloud Pak for Data
- Fedora 36 update for containerd
- Fedora 35 update for containerd, moby-engine
- Fedora 34 update for containerd, moby-engine
- Multiple vulnerabilities in IBM DB2 Data Management Console