Improper Preservation of Permissions in runc - CVE-2023-25809
Published: March 30, 2023
Vulnerability identifier: #VU74189
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25809
CWE-ID: CWE-281
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to the rootless "/sys/fs/cgroup" is writable when cgroupns is not unshared. A local administrator can gain the write access to user-owned cgroup hierarchy "/sys/fs/cgroup/user.slice/..." on the host.
Affected software
runc
Cloud Pak for Data
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Storage Defender - Resiliency Service
DB2 Data Management Console
DB2 Data Management Console on CPD
ObjectScale
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
IBM supplied MQ Advanced container images
IBM Sterling Order Management
Oracle Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Ubuntu
openEuler
QRadar Suite
IBM Edge Application Manager
Dell EMC Container Storage Modules
Red Hat OpenShift Container Platform
runc (Ubuntu package)
toolbox-tests
toolbox
udica
docker-runc
runc
runc-debuginfo
runc (Red Hat package)
app-containers/runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
crun
fuse-overlayfs
skopeo
skopeo-tests
buildah
buildah-tests
containers-common
conmon
container-selinux
crit
criu-libs
criu
python3-criu
criu-devel
libslirp-devel
libslirp
python3-podman
podman-tests
podman-docker
podman-remote
podman-plugins
podman-gvproxy
podman-catatonit
podman
cockpit-podman
IBM MQ Operator
Cloud Pak for Data
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Storage Defender - Resiliency Service
DB2 Data Management Console
DB2 Data Management Console on CPD
ObjectScale
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
IBM supplied MQ Advanced container images
IBM Sterling Order Management
Oracle Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Ubuntu
openEuler
QRadar Suite
IBM Edge Application Manager
Dell EMC Container Storage Modules
Red Hat OpenShift Container Platform
runc (Ubuntu package)
toolbox-tests
toolbox
udica
docker-runc
runc
runc-debuginfo
runc (Red Hat package)
app-containers/runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
crun
fuse-overlayfs
skopeo
skopeo-tests
buildah
buildah-tests
containers-common
conmon
container-selinux
crit
criu-libs
criu
python3-criu
criu-devel
libslirp-devel
libslirp
python3-podman
podman-tests
podman-docker
podman-remote
podman-plugins
podman-gvproxy
podman-catatonit
podman
cockpit-podman
IBM MQ Operator
How to mitigate CVE-2023-25809
Install updates from vendor's website.
runc - update to 1.1.5
QRadar Suite - update to 1.10.21.0
Storage Defender - Resiliency Service - update to 2.0.11
DB2 Data Management Console - update to 3.1.13.1
DB2 Data Management Console on CPD - update to 4.7.2
runc (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.4-0ubuntu1~18.04.2, 1.1.4-0ubuntu1~20.04.3, 1.1.4-0ubuntu1~22.04.3, 1.1.4-0ubuntu1~22.10.3, 1.1.4-0ubuntu3.1
toolbox-tests - update to 0.0.99.4-5.0.1
toolbox - update to 0.0.99.4-5.0.1
udica - update to 0.2.6-20
docker-runc - update to 1.1.3-13
runc - update to 1.1.5-1
runc - addressed in versions 1.1.5-16.29.1, 1.1.5-150000.41.1
runc-debuginfo - addressed in versions 1.1.5-16.29.1, 1.1.5-150000.41.1
runc (Red Hat package) - update to 1.1.9-1.el9
app-containers/runc - update to 1.1.12
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.1-1
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins - update to 1.3.0-8.0.1
ObjectScale - update to 1.4.0
Dell EMC Container Storage Modules - update to 1.7.0
aardvark-dns - update to 1.7.0-2.0.1
netavark - update to 1.7.0-2.0.1
crun - update to 1.8.7-1
fuse-overlayfs - update to 1.12-1.0.1
skopeo - update to 1.13.3-3.0.1
skopeo-tests - update to 1.13.3-3.0.1
buildah - update to 1.31.3-1
buildah-tests - update to 1.31.3-1
containers-common - update to 1-71.0.1
IBM MQ Operator - addressed in versions 2.0.13, 2.4.2
conmon - update to 2.1.8-1
container-selinux - update to 2.221.0-1
IBM Cloud Pak for Watson AIOps - update to 3.7.2
crit - update to 3.18-5
criu-libs - update to 3.18-5
criu - update to 3.18-5
python3-criu - update to 3.18-5
criu-devel - update to 3.18-5
libslirp-devel - update to 4.4.0-1
libslirp - update to 4.4.0-1
python3-podman - update to 4.6.0-1
podman-tests - update to 4.6.1-8.0.1
podman-docker - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman - update to 4.6.1-8.0.1
DB2 on Cloud Pak for Data - update to 4.8.4
Cloud Pak for Data - update to 4.8.5
Red Hat OpenShift Container Platform - update to 4.13.0
IBM supplied MQ Advanced container images - update to 9.3.0.10-r1
IBM Sterling Order Management - update to 10.0.2403.1
cockpit-podman - update to 75-1
QRadar Suite - update to 1.10.21.0
Storage Defender - Resiliency Service - update to 2.0.11
DB2 Data Management Console - update to 3.1.13.1
DB2 Data Management Console on CPD - update to 4.7.2
runc (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.4-0ubuntu1~18.04.2, 1.1.4-0ubuntu1~20.04.3, 1.1.4-0ubuntu1~22.04.3, 1.1.4-0ubuntu1~22.10.3, 1.1.4-0ubuntu3.1
toolbox-tests - update to 0.0.99.4-5.0.1
toolbox - update to 0.0.99.4-5.0.1
udica - update to 0.2.6-20
docker-runc - update to 1.1.3-13
runc - update to 1.1.5-1
runc - addressed in versions 1.1.5-16.29.1, 1.1.5-150000.41.1
runc-debuginfo - addressed in versions 1.1.5-16.29.1, 1.1.5-150000.41.1
runc (Red Hat package) - update to 1.1.9-1.el9
app-containers/runc - update to 1.1.12
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.1-1
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins - update to 1.3.0-8.0.1
ObjectScale - update to 1.4.0
Dell EMC Container Storage Modules - update to 1.7.0
aardvark-dns - update to 1.7.0-2.0.1
netavark - update to 1.7.0-2.0.1
crun - update to 1.8.7-1
fuse-overlayfs - update to 1.12-1.0.1
skopeo - update to 1.13.3-3.0.1
skopeo-tests - update to 1.13.3-3.0.1
buildah - update to 1.31.3-1
buildah-tests - update to 1.31.3-1
containers-common - update to 1-71.0.1
IBM MQ Operator - addressed in versions 2.0.13, 2.4.2
conmon - update to 2.1.8-1
container-selinux - update to 2.221.0-1
IBM Cloud Pak for Watson AIOps - update to 3.7.2
crit - update to 3.18-5
criu-libs - update to 3.18-5
criu - update to 3.18-5
python3-criu - update to 3.18-5
criu-devel - update to 3.18-5
libslirp-devel - update to 4.4.0-1
libslirp - update to 4.4.0-1
python3-podman - update to 4.6.0-1
podman-tests - update to 4.6.1-8.0.1
podman-docker - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman - update to 4.6.1-8.0.1
DB2 on Cloud Pak for Data - update to 4.8.4
Cloud Pak for Data - update to 4.8.5
Red Hat OpenShift Container Platform - update to 4.13.0
IBM supplied MQ Advanced container images - update to 9.3.0.10-r1
IBM Sterling Order Management - update to 10.0.2403.1
cockpit-podman - update to 75-1
External References
Related Security Bulletins
- Multiple vulnerabilities in runc
- SUSE update for runc
- SUSE update for runc
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Ubuntu update for runc
- Ubuntu update for runc
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in Dell Container Storage Modules
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in IBM MQ Operator
- Red Hat Enterprise Linux 9 update for runc
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 8 update for the container-tools:4.0 module
- openEuler 22.03 LTS SP1 update for runc
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in IBM QRadar Suite software
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data
- Multiple vulnerabilities in Dell ObjectScale
- Gentoo update for runc
- Multiple vulnerabilities in IBM Cloud Pak for Data
- Amazon Linux AMI update for runc
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in IBM DB2 Data Management Console