当前位置:网站首页>Runc symbolic link mount and container escape vulnerability alert (cve-2021-30465)
Runc symbolic link mount and container escape vulnerability alert (cve-2021-30465)
2022-06-23 06:01:00 【Foxconn quality inspector zhangquandan】
runC Is a basis OCI(Open Container Initiative) Standard for creating and running containers CLI Tools , at present Docker The interior of the engine is also based on runc Built . 2019 year 2 month 11 Japan , Researchers passed oss-security Mailing list, (https://www.openwall.com/list… ) Disclosed runc Details of the container escape vulnerability , according to OpenWall The provisions of the EXP Will be in 7 Days later 2019 year 2 month 18 Open to the public .
This vulnerability may allow for root The container running as executes arbitrary code on the host as a privileged user . actually , This means that the container may break Docker host ( Cover Runc CLI), All you need is to be able to use root To run the container . Attackers can use infected Docker Mirror or run against an uninfected, running container exec command . Known mitigation measures for this problem include :
- Run with a read-only host file system
- Run user namespace
- Not running in a container root
- Correctly configured AppArmor / SELinux Strategy ( The current default policy is insufficient )
Rancher The team responded immediately
After receiving the disclosure email ,RancherOS The team immediately tried to script the attack , Running a very simple script in a common container completes the attack on the host , Put the runc Replaced with another program .
After the vulnerability is disclosed ,Docker It was released at the first time 18.09.2, Users can upgrade to this version to fix this vulnerability .Rancher Labs The R & D team also responded immediately , Released Rancher v2.1.6、v2.0.11 and v1.6.26, These three new versions Rancher Support Docker Just released 18.09.2,Rancher Users can upgrade Docker Version to prevent being affected by this security vulnerability .
Can't upgrade Docker What about the version
Usually due to various factors , Many users' production environments are not easy to upgrade too new Docker edition .
To help, I can't follow Docker The official recommendation is to upgrade to the latest version Docker 18.09.2 Of users to solve this problem ,Rancher Labs The team goes further , The fix has been reverse ported to all versions of Docker, by Docker 1.12.6、1.13.1、17.03.2、17.06.2、17.09.1、18.03.1 and 18.06.1 Provide patches , Fix this vulnerability ! Relevant patches and installation instructions , Please refer to :
https://github.com/rancher/ru….
边栏推荐
- 如何指定pig-register项目日志的输出路径
- ant使用总结(三):批量打包apk
- Real MySQL interview questions (XXVI) -- didi 2020 written examination questions
- Pat class B 1014 C language
- 数字藏品市场才刚刚开始
- Pat class B 1015 C language
- How can digital collections empower economic entities?
- 数字藏品——新的投资机遇
- jvm-01. Instruction rearrangement
- Pat class B 1016 C language
猜你喜欢

Software design and Development Notes 2: serial port debugging tool based on QT design

ant使用总结(二):相关命令说明

Centos7 installation of postgresql8.2.15 and creation of stored procedures

Heimdall database proxy scale out 20 times

The performance of nonstandard sprintf code in different platforms

True question of MySQL interview (29) -- case - finding favorite movies

True MySQL interview question (24) -- row column exchange

True MySQL interview question (XXII) -- condition screening and grouping screening after table connection

What benefits have digital collections enabled the real industry to release?

技术开发团队视角看到的数字藏品机遇与挑战
随机推荐
How to specify the output path of pig register Project Log
Adnroid activity screenshot save display to album view display picture animation disappear
【Cocos2d-x】自定义环形菜单
Excel sheet column title for leetcode Title Resolution
The traditional Internet like platform may no longer exist, and a new industry integrating industrial characteristics and Internet characteristics
[OWT] OWT client native P2P E2E test vs2017 build 6: modify script automatic generation vs Project
Leetcode topic analysis: factorial training zeroes
Pat class B 1023 minimum decimals
PAT 乙等 1013 C语言
Behind the hot digital collections, a strong technical team is needed to support the northern technical team
Advanced Mathematics (Seventh Edition) Tongji University exercises 1-9 personal solutions
MDM data cleaning function development description
Genetic engineering of AI art? Use # artbreeder to change any shape of the image
Advanced Mathematics (Seventh Edition) Tongji University exercises 1-8 personal solutions
JS面试题----防抖函数
jvm-06.垃圾回收器
jvm-01. Instruction rearrangement
The author believes that the so-called industrial Internet is a process of deep integration of industry and the Internet
Leetcode topic resolution divide two integers
HierarchyViewer工具找不到 HierarchyViewer位置
https://cloud.tencent.com/document/product/457/72048