Improper access control in runc - CVE-2023-27561

 

Improper access control in runc - CVE-2023-27561

Published: March 30, 2023


Vulnerability identifier: #VU74190
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27561
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to improper access restrictions in the libcontainer/rootfs_linux.go. A local user can gain elevated privileges on the target system.


Affected software

runc
Cloud Pak for Data
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Storage Defender - Resiliency Service
DB2 Data Management Console
DB2 Data Management Console on CPD
ObjectScale
Dell EMC Streaming Data Platform
Cloud Kubernetes Service
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
IBM supplied MQ Advanced container images
IBM Sterling Order Management
Oracle Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Ubuntu
Fedora
QRadar Suite
Red Hat OpenShift Container Platform
Dell EMC Container Storage Modules
runc (Ubuntu package)
toolbox-tests
toolbox
udica
containernetworking-plugins (Red Hat package)
runc
runc-debuginfo
runc (Red Hat package)
golang-github-opencontainers-runc
app-containers/runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
crun
skopeo (Red Hat package)
fuse-overlayfs
skopeo
skopeo-tests
cri-o (Red Hat package)
buildah (Red Hat package)
buildah
buildah-tests
containers-common
conmon (Red Hat package)
conmon
nmstate (Red Hat package)
container-selinux (Red Hat package)
container-selinux
openvswitch3.1 (Red Hat package)
criu-libs
criu-devel
crit
criu
python3-criu
libslirp-devel
libslirp
podman (Red Hat package)
python3-podman
podman
podman-docker
podman-catatonit
podman-gvproxy
podman-plugins
podman-remote
podman-tests
openshift (Red Hat package)
openshift-ansible (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift-clients (Red Hat package)
openshift-kuryr (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
openstack-ironic (Red Hat package)
ovn23.06 (Red Hat package)
cockpit-podman
IBM MQ Operator
APEX Cloud Platform for Red Hat OpenShift
IBM Cloud Transformation Advisor
IBM InfoSphere Information Server

How to mitigate CVE-2023-27561

Install update from vendor's website.

runc - update to 1.1.5
QRadar Suite - update to 1.10.21.0
Storage Defender - Resiliency Service - update to 2.0.11
DB2 Data Management Console - update to 3.1.13.1
DB2 Data Management Console on CPD - update to 4.7.2
Red Hat OpenShift Container Platform - addressed in versions 4.12.23, 4.13.0, 4.13.4, 4.13.5, 4.13.6
runc (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.4-0ubuntu1~18.04.2, 1.1.4-0ubuntu1~20.04.3, 1.1.4-0ubuntu1~22.04.3, 1.1.4-0ubuntu1~22.10.3, 1.1.4-0ubuntu3.1
toolbox-tests - update to 0.0.99.4-5.0.1
toolbox - update to 0.0.99.4-5.0.1
udica - update to 0.2.6-20
containernetworking-plugins (Red Hat package) - addressed in versions 1.0.1-7.rhaos4.13.el8, 1.0.1-8.rhaos4.13.el8
runc - update to 1.1.5-1
runc - addressed in versions 1.1.5-16.29.1, 1.1.5-150000.41.1
runc-debuginfo - addressed in versions 1.1.5-16.29.1, 1.1.5-150000.41.1
runc - addressed in versions 1.1.6-1.fc36, 1.1.6-1.fc37, 1.1.6-1.fc38
runc (Red Hat package) - addressed in versions 1.1.6-4.rhaos4.13.el8, 1.1.9-1.el9
golang-github-opencontainers-runc - addressed in versions 1.1.8-1.fc37, 1.1.8-1.fc38, 1.1.8-2.fc37, 1.1.8-2.fc38
app-containers/runc - update to 1.1.12
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.1-1
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins - update to 1.3.0-8.0.1
ObjectScale - update to 1.4.0
Dell EMC Streaming Data Platform - update to 1.7.0
Dell EMC Container Storage Modules - update to 1.7.0
aardvark-dns - update to 1.7.0-2.0.1
netavark - update to 1.7.0-2.0.1
crun - update to 1.8.7-1
skopeo (Red Hat package) - addressed in versions 1.11.2-2.rhaos4.13.el8, 1.11.2-2.1.rhaos4.13.el9
fuse-overlayfs - update to 1.12-1.0.1
skopeo - update to 1.13.3-3.0.1
skopeo-tests - update to 1.13.3-3.0.1
Cloud Kubernetes Service - addressed in versions 1.24.12_1564, 1.25.8_1541, 1.26.5_1538
cri-o (Red Hat package) - addressed in versions 1.26.3-9.rhaos4.13.git994242a.el8, 1.26.3-10.rhaos4.13.git78941bf.el8, 1.26.3-10.rhaos4.13.git994242a.el9, 1.26.3-11.rhaos4.13.git78941bf.el9
buildah (Red Hat package) - addressed in versions 1.29.1-2.rhaos4.13.el8, 1.29.1-2.1.rhaos4.13.el9
buildah - update to 1.31.3-1
buildah-tests - update to 1.31.3-1
containers-common - update to 1-71.0.1
IBM MQ Operator - addressed in versions 2.0.13, 2.4.2
conmon (Red Hat package) - addressed in versions 2.1.7-2.rhaos4.13.el8, 2.1.7-2.1.rhaos4.13.el9
conmon - update to 2.1.8-1
nmstate (Red Hat package) - update to 2.2.12-1.rhaos4.13.el8
container-selinux (Red Hat package) - update to 2.215.0-1.rhaos4.13.el8
container-selinux - update to 2.221.0-1
openvswitch3.1 (Red Hat package) - update to 3.1.0-32.el9fdp
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
IBM Cloud Transformation Advisor - update to 3.5.2
IBM Cloud Pak for Watson AIOps - update to 3.7.2
criu-libs - update to 3.18-5
criu-devel - update to 3.18-5
crit - update to 3.18-5
criu - update to 3.18-5
python3-criu - update to 3.18-5
libslirp-devel - update to 4.4.0-1
libslirp - update to 4.4.0-1
podman (Red Hat package) - addressed in versions 4.4.1-4.rhaos4.13.el8, 4.4.1-5.1.rhaos4.13.el9
python3-podman - update to 4.6.0-1
podman - update to 4.6.1-8.0.1
podman-docker - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
podman-tests - update to 4.6.1-8.0.1
DB2 on Cloud Pak for Data - update to 4.8.4
Cloud Pak for Data - update to 4.8.5
openshift (Red Hat package) - addressed in versions 4.13.0-202306072143.p0.g7d22122.assembly.stream.el8, 4.13.0-202306072143.p0.g7d22122.assembly.stream.el9, 4.13.0-202307132344.p0.gf245ced.assembly.stream.el8, 4.13.0-202307132344.p0.gf245ced.assembly.stream.el9
openshift-ansible (Red Hat package) - addressed in versions 4.13.0-202306230038.p0.g148be47.assembly.stream.el8, 4.13.0-202306230038.p0.g148be47.assembly.stream.el9
openshift4-aws-iso (Red Hat package) - update to 4.13.0-202306230038.p0.gd2acdd5.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el8, 4.13.0-202306230038.p0.ge4c9a6a.assembly.stream.el9
openshift-kuryr (Red Hat package) - update to 4.13.0-202306281017.p0.g5baee73.assembly.stream.el8
kernel (Red Hat package) - addressed in versions 5.14.0-284.18.1.el9_2, 5.14.0-284.23.1.el9_2
kernel-rt (Red Hat package) - addressed in versions 5.14.0-284.18.1.rt14.303.el9_2, 5.14.0-284.23.1.rt14.308.el9_2
IBM supplied MQ Advanced container images - update to 9.3.0.10-r1
IBM Sterling Order Management - update to 10.0.2403.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
openstack-ironic (Red Hat package) - update to 21.3.1-0.20230706125653.c8f8157.el9
ovn23.06 (Red Hat package) - update to 23.06.0-13.el9fdp
cockpit-podman - update to 75-1

External References

Related Security Bulletins