Security restrictions bypass in containerd - CVE-2021-43816

 

Security restrictions bypass in containerd - CVE-2021-43816

Published: January 6, 2022


Vulnerability identifier: #VU59237
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43816
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a logic issue, which causes arbitrary files and directories on the host to be relabeled to match the container process label through the use of specially-configured bind mounts in a hostPath volume. A local user can place the in-container location of the hostPath volume mount at either `/etc/hosts`, `/etc/hostname`, or `/etc/resolv.conf` and gain read/write access to arbitrary file on the system.

The vulnerability affects containerd installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS.


Affected software

containerd
DB2 Data Management Console
DB2 on Cloud Pak for Data
DB2 Data Management Console on CPD
IBM Cloud Pak for Security
Red Hat Advanced Cluster Management for Kubernetes
APEX Cloud Platform for Red Hat OpenShift
QRadar Suite
IBM Edge Application Manager
Fedora
containerd
Cloud Pak for Data

How to mitigate CVE-2021-43816

Install updates from vendor's website.

containerd - update to 1.5.9
QRadar Suite - update to 1.10.19.0
DB2 Data Management Console - update to 3.1.13.1
containerd - addressed in versions 1.5.9-1.fc34, 1.5.9-1.fc35, 1.5.9-1.fc36, 1.6.0~rc.2-2.fc35, 1.6.0~rc.2-3.fc34
Red Hat Advanced Cluster Management for Kubernetes - update to 2.5.0
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
DB2 on Cloud Pak for Data - update to 4.8.4
Cloud Pak for Data - update to 4.8.5
DB2 Data Management Console on CPD - update to 5.1.2

External References

Related Security Bulletins