Debian Security Advisory
DLA-2841-1 runc -- LTS security update
- Date Reported:
- 06 Dec 2021
- Affected Packages:
- runc
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2021-43784.
- More information:
-
It was discovered that there was an overflow issue in runc, the runtime for the Open Container Project, often used with Docker.
The Netlink 'bytemsg' length field could have allowed an attacker to override Netlink-based container configurations. This vulnerability required the attacker to have some control over the configuration of the container, but would have allowed the attacker to bypass the namespace restrictions of the container by simply adding their own Netlink payload which disables all namespaces.
For Debian 9
Stretch
, these problems have been fixed in version 0.1.1+dfsg1-2+deb9u3.We recommend that you upgrade your runc packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS