Improper Preservation of Permissions in runc - CVE-2023-28642
Published: March 30, 2023
Vulnerability identifier: #VU74193
CSH Severity: Medium
CVSS v4 BT: 1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-28642
CWE-ID: CWE-281
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper preservation of permissions in the AppArmor and SELinux when /proc inside the container is symlinked with a specific mount configuration. A remote attacker can gain access to the target application.
Affected software
runc
Cloud Pak for Data
Oracle Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Ubuntu
openEuler
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Storage Defender - Resiliency Service
DB2 Data Management Console
DB2 Data Management Console on CPD
ObjectScale
Cloud Kubernetes Service
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
IBM Sterling Order Management
QRadar Suite
IBM Edge Application Manager
Dell EMC Container Storage Modules
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
runc (Ubuntu package)
toolbox
toolbox-tests
udica
docker-runc
runc
runc-debuginfo
runc (Red Hat package)
app-containers/runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
netavark
aardvark-dns
crun
fuse-overlayfs
skopeo
skopeo-tests
buildah-tests
buildah
containers-common
conmon
container-selinux
criu-libs
criu-devel
criu
crit
python3-criu
libslirp
libslirp-devel
python3-podman
podman-docker
podman-remote
podman-tests
podman-plugins
podman-gvproxy
podman-catatonit
podman
cockpit-podman
IBM MQ Operator
IBM InfoSphere Information Server
Cloud Pak for Data
Oracle Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Ubuntu
openEuler
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Storage Defender - Resiliency Service
DB2 Data Management Console
DB2 Data Management Console on CPD
ObjectScale
Cloud Kubernetes Service
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
IBM Sterling Order Management
QRadar Suite
IBM Edge Application Manager
Dell EMC Container Storage Modules
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
runc (Ubuntu package)
toolbox
toolbox-tests
udica
docker-runc
runc
runc-debuginfo
runc (Red Hat package)
app-containers/runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
netavark
aardvark-dns
crun
fuse-overlayfs
skopeo
skopeo-tests
buildah-tests
buildah
containers-common
conmon
container-selinux
criu-libs
criu-devel
criu
crit
python3-criu
libslirp
libslirp-devel
python3-podman
podman-docker
podman-remote
podman-tests
podman-plugins
podman-gvproxy
podman-catatonit
podman
cockpit-podman
IBM MQ Operator
IBM InfoSphere Information Server
How to mitigate CVE-2023-28642
Install updates from vendor's website.
runc - update to 1.1.5
QRadar Suite - update to 1.10.21.0
Storage Defender - Resiliency Service - update to 2.0.11
DB2 Data Management Console - update to 3.1.13.1
DB2 Data Management Console on CPD - update to 4.7.2
runc (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.4-0ubuntu1~18.04.2, 1.1.4-0ubuntu1~20.04.3, 1.1.4-0ubuntu1~22.04.3, 1.1.4-0ubuntu1~22.10.3, 1.1.4-0ubuntu3.1
toolbox - update to 0.0.99.4-5.0.1
toolbox-tests - update to 0.0.99.4-5.0.1
udica - update to 0.2.6-20
docker-runc - addressed in versions 1.0.0 rc3-212, 1.0.0 rc3-310, 1.1.3-13
runc - update to 1.1.5-1
runc-debuginfo - addressed in versions 1.1.5-16.29.1, 1.1.5-150000.41.1
runc - addressed in versions 1.1.5-16.29.1, 1.1.5-150000.41.1
runc (Red Hat package) - update to 1.1.9-1.el9
app-containers/runc - update to 1.1.12
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.1-1
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins - update to 1.3.0-8.0.1
ObjectScale - update to 1.4.0
Dell EMC Container Storage Modules - update to 1.7.0
netavark - update to 1.7.0-2.0.1
aardvark-dns - update to 1.7.0-2.0.1
crun - update to 1.8.7-1
fuse-overlayfs - update to 1.12-1.0.1
skopeo - update to 1.13.3-3.0.1
skopeo-tests - update to 1.13.3-3.0.1
Cloud Kubernetes Service - addressed in versions 1.24.12_1564, 1.25.8_1541, 1.26.5_1538
buildah-tests - update to 1.31.3-1
buildah - update to 1.31.3-1
containers-common - update to 1-71.0.1
IBM MQ Operator - addressed in versions 2.0.13, 2.4.1
conmon - update to 2.1.8-1
container-selinux - update to 2.221.0-1
IBM Cloud Pak for Watson AIOps - update to 3.7.2
criu-libs - update to 3.18-5
criu-devel - update to 3.18-5
criu - update to 3.18-5
crit - update to 3.18-5
python3-criu - update to 3.18-5
libslirp - update to 4.4.0-1
libslirp-devel - update to 4.4.0-1
python3-podman - update to 4.6.0-1
podman-docker - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
podman-tests - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman - update to 4.6.1-8.0.1
DB2 on Cloud Pak for Data - update to 4.8.4
Cloud Pak for Data - update to 4.8.5
Red Hat OpenShift Container Platform - update to 4.13.0
IBM Sterling Order Management - update to 10.0.2403.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
cockpit-podman - update to 75-1
QRadar Suite - update to 1.10.21.0
Storage Defender - Resiliency Service - update to 2.0.11
DB2 Data Management Console - update to 3.1.13.1
DB2 Data Management Console on CPD - update to 4.7.2
runc (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.4-0ubuntu1~18.04.2, 1.1.4-0ubuntu1~20.04.3, 1.1.4-0ubuntu1~22.04.3, 1.1.4-0ubuntu1~22.10.3, 1.1.4-0ubuntu3.1
toolbox - update to 0.0.99.4-5.0.1
toolbox-tests - update to 0.0.99.4-5.0.1
udica - update to 0.2.6-20
docker-runc - addressed in versions 1.0.0 rc3-212, 1.0.0 rc3-310, 1.1.3-13
runc - update to 1.1.5-1
runc-debuginfo - addressed in versions 1.1.5-16.29.1, 1.1.5-150000.41.1
runc - addressed in versions 1.1.5-16.29.1, 1.1.5-150000.41.1
runc (Red Hat package) - update to 1.1.9-1.el9
app-containers/runc - update to 1.1.12
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.1-1
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins - update to 1.3.0-8.0.1
ObjectScale - update to 1.4.0
Dell EMC Container Storage Modules - update to 1.7.0
netavark - update to 1.7.0-2.0.1
aardvark-dns - update to 1.7.0-2.0.1
crun - update to 1.8.7-1
fuse-overlayfs - update to 1.12-1.0.1
skopeo - update to 1.13.3-3.0.1
skopeo-tests - update to 1.13.3-3.0.1
Cloud Kubernetes Service - addressed in versions 1.24.12_1564, 1.25.8_1541, 1.26.5_1538
buildah-tests - update to 1.31.3-1
buildah - update to 1.31.3-1
containers-common - update to 1-71.0.1
IBM MQ Operator - addressed in versions 2.0.13, 2.4.1
conmon - update to 2.1.8-1
container-selinux - update to 2.221.0-1
IBM Cloud Pak for Watson AIOps - update to 3.7.2
criu-libs - update to 3.18-5
criu-devel - update to 3.18-5
criu - update to 3.18-5
crit - update to 3.18-5
python3-criu - update to 3.18-5
libslirp - update to 4.4.0-1
libslirp-devel - update to 4.4.0-1
python3-podman - update to 4.6.0-1
podman-docker - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
podman-tests - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman - update to 4.6.1-8.0.1
DB2 on Cloud Pak for Data - update to 4.8.4
Cloud Pak for Data - update to 4.8.5
Red Hat OpenShift Container Platform - update to 4.13.0
IBM Sterling Order Management - update to 10.0.2403.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
cockpit-podman - update to 75-1
External References
Related Security Bulletins
- Multiple vulnerabilities in runc
- SUSE update for runc
- SUSE update for runc
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Ubuntu update for runc
- Ubuntu update for runc
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Cloud Kubernetes Service
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in Dell Container Storage Modules
- Multiple vulnerabilities in Dell Data Protection Central
- Red Hat Enterprise Linux 9 update for runc
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 8 update for the container-tools:4.0 module
- Red Hat Enterprise Linux 8 update for the container-tools:3.0 module
- openEuler 22.03 LTS SP1 update for runc
- openEuler 20.03 LTS SP1 update for runc
- openEuler 20.03 LTS SP3 update for runc
- openEuler 22.03 LTS update for runc
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in IBM QRadar Suite software
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data
- Multiple vulnerabilities in Dell ObjectScale
- Gentoo update for runc
- Multiple vulnerabilities in IBM Cloud Pak for Data
- Amazon Linux AMI update for runc
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in IBM DB2 Data Management Console