rpm package
almalinux/runc
pkg:rpm/almalinux/runc
Vulnerabilities (111)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-21698 | Hig | 7.5 | < 1:1.0.3-2.module_el8.6.0+2878+e681bc44 | 1:1.0.3-2.module_el8.6.0+2878+e681bc44 | Feb 15, 2022 | client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounde | |
| CVE-2021-4024 | Med | 6.5 | < 1:1.1.12-5.module_el8.10.0+3909+6e1c1eb7 | 1:1.1.12-5.module_el8.10.0+3909+6e1c1eb7 | Dec 23, 2021 | A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is op | |
| CVE-2021-43784 | Med | 6.0 | < 4:1.1.9-1.el9 | 4:1.1.9-1.el9 | Dec 6, 2021 | runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used internally as a serialization system for specifying the relevant container configuration to the `C` portion of the code (responsible for the based namespac | |
| CVE-2021-33198 | Hig | 7.5 | < 1:1.1.12-5.module_el8.10.0+3909+6e1c1eb7 | 1:1.1.12-5.module_el8.10.0+3909+6e1c1eb7 | Aug 2, 2021 | In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method. | |
| CVE-2021-20188 | Hig | 7.0 | < 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43 | 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43 | Feb 11, 2021 | A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even if owned by the root use | |
| CVE-2020-1983 | Hig | 7.5 | < 1.0.0-66.rc10.module_el8.5.0+2635+e4386a39 | 1.0.0-66.rc10.module_el8.5.0+2635+e4386a39 | Apr 22, 2020 | A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service. | |
| CVE-2020-10696 | Hig | 8.8 | < 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43 | 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43 | Mar 31, 2020 | A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions. | |
| CVE-2019-19921 | Hig | 7.0 | < 4:1.1.9-1.el9 | 4:1.1.9-1.el9 | Feb 12, 2020 | runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vul | |
| CVE-2020-7039 | Med | 5.6 | < 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43 | 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43 | Jan 16, 2020 | tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code. | |
| CVE-2019-9514 | Hig | 7.5 | < 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43 | 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43 | Aug 13, 2019 | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer | |
| CVE-2019-9512 | Hig | 7.5 | < 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43 | 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43 | Aug 13, 2019 | Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consum |
- affected < 1:1.0.3-2.module_el8.6.0+2878+e681bc44fixed 1:1.0.3-2.module_el8.6.0+2878+e681bc44
client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounde
- affected < 1:1.1.12-5.module_el8.10.0+3909+6e1c1eb7fixed 1:1.1.12-5.module_el8.10.0+3909+6e1c1eb7
A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is op
- affected < 4:1.1.9-1.el9fixed 4:1.1.9-1.el9
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used internally as a serialization system for specifying the relevant container configuration to the `C` portion of the code (responsible for the based namespac
- affected < 1:1.1.12-5.module_el8.10.0+3909+6e1c1eb7fixed 1:1.1.12-5.module_el8.10.0+3909+6e1c1eb7
In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.
- affected < 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43fixed 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43
A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even if owned by the root use
- affected < 1.0.0-66.rc10.module_el8.5.0+2635+e4386a39fixed 1.0.0-66.rc10.module_el8.5.0+2635+e4386a39
A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
- affected < 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43fixed 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
- affected < 4:1.1.9-1.el9fixed 4:1.1.9-1.el9
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vul
- affected < 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43fixed 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43
tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.
- affected < 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43fixed 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer
- affected < 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43fixed 1.0.0-56.rc5.dev.git2abd837.module_el8.3.0+2044+12421f43
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consum
Page 6 of 6