Race condition in runc - CVE-2024-45310
Published: September 3, 2024
Vulnerability details
The vulnerability allows a remote attacker to crate empty files and directories on the host.
The vulnerability exists due to a race condition when handling containers with custom configuration. A remote attacker can trick the victim into running a specially crafted Docker or Kubernetes container, which can be used to share a volume between two containers and then exploit a race with os.MkdirAll to create empty files or directories in arbitrary locations in the host filesystem.
Successful exploitation of the vulnerability may allow an attacker to perform a denial of service attack against the host system.
Affected software
PowerStore 9200T
PowerStore 9000T
PowerStore 7000T
PowerStore 5200T
PowerStore 500T
PowerStore 5000T
PowerStore 1000T
PowerStore 1200T
PowerStore 3000T
PowerStore 3200T
PowerStoreT OS
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
BIG-IP Next CNF
BIG-IP Next SPK
BIG-IP Next for Kubernetes
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
HPC Module
openSUSE Leap
openEuler
Anolis OS
IBM Concert Software
watsonx.data
Guardium Data Security Center (GDSC)
Robotic Process Automation for Cloud Pak
Red Hat OpenShift on IBM Cloud
Cloud Pak for Data
libsquashfuse0
squashfuse-debugsource
libsquashfuse0-debuginfo
squashfuse
squashfuse-debuginfo
squashfuse-tools-debuginfo
squashfuse-devel
squashfuse-tools
docker-runc
runc
runc-doc
runc-debuginfo
apptainer-debuginfo
apptainer
apptainer-sle15_7
apptainer-sle16
apptainer-sle15_6
apptainer-leap
kubevirt-manifests
kubevirt-virtctl-debuginfo
kubevirt-virtctl
Dell EMC VxRail Appliance
How to mitigate CVE-2024-45310
IBM Concert Software - update to 1.1.0
watsonx.data - update to 2.2
Guardium Data Security Center (GDSC) - update to 3.8.5
Cloud Pak for Data - update to 5.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.2
libsquashfuse0 - update to 0.5.0-150600.3.2.1
squashfuse-debugsource - update to 0.5.0-150600.3.2.1
libsquashfuse0-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse - update to 0.5.0-150600.3.2.1
squashfuse-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-tools-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-devel - update to 0.5.0-150600.3.2.1
squashfuse-tools - update to 0.5.0-150600.3.2.1
docker-runc - addressed in versions 1.0.0 rc3-228, 1.1.3-25, 1.1.3-30
runc - addressed in versions 1.1.3-30, 1.1.3-31, 1.1.8-21
runc - update to 1.1.12-2
runc-doc - update to 1.1.12-2
runc - addressed in versions 1.1.14-16.55.1, 1.1.14-150000.70.1, 1.2.6-16.60.2
runc-debuginfo - addressed in versions 1.1.14-16.55.1, 1.1.14-150000.70.1, 1.2.6-16.60.2
apptainer-debuginfo - update to 1.4.5-150600.4.12.1
apptainer - update to 1.4.5-150600.4.12.1
apptainer-sle15_7 - update to 1.4.5-150600.4.12.1
apptainer-sle16 - update to 1.4.5-150600.4.12.1
apptainer-sle15_6 - update to 1.4.5-150600.4.12.1
apptainer-leap - update to 1.4.5-150600.4.12.1
kubevirt-manifests - update to 1.7.0-150700.3.16.2
kubevirt-virtctl-debuginfo - update to 1.7.0-150700.3.16.2
kubevirt-virtctl - update to 1.7.0-150700.3.16.2
PowerStoreT OS - update to 3.6.1.5-2456810
Red Hat OpenShift on IBM Cloud - addressed in versions 4.13.51 1593, 4.15.35 1561, 4.16.15 1539
Dell EMC VxRail Appliance - update to 8.0.311
External References
Related Security Bulletins
- Race condition in runc
- SUSE update for runc
- openEuler 22.03 LTS SP3 update for runc
- openEuler 20.03 LTS SP4 update for runc
- openEuler 22.03 LTS SP1 update for runc
- openEuler 24.03 LTS update for runc
- SUSE update for runc
- openEuler 22.03 LTS SP4 update for runc
- Multiple vulnerabilities in Dell VxRail Appliance
- Red Hat OpenShift on IBM Cloud update for runc
- Anolis OS update for runc
- SUSE update for runc
- Multiple vulnerabilities in Dell PowerStoreT OS
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- IBM Cloud Pak for Data update for runc
- Race condition in BIG-IP Next OTEL collectors
- IBM watsonx.data update for runc
- Multiple vulnerabilities in IBM Guardium Data Security Center
- SUSE update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-t
- SUSE update for apptainer