天下漏洞,尽知其名
HIGH

CVE-2024-21626 RnW29/cve-2024-21626-runc-lab

影响攻击者可突破容器隔离,在宿主机上执行任意命令

AI 研判

CVE-2024-21626 是 runc 容器运行时中的文件描述符泄漏漏洞。由于 runc 在处理工作目录时未正确关闭内部文件描述符,攻击者可通过恶意容器镜像或配置利用该泄漏的 fd 逃逸到宿主机文件系统。

影响范围

runc

runc 1.1.11 及更早版本受影响,1.1.12 版本修复;具体受影响范围请以官方公告为准。

漏洞详情

该漏洞属于容器逃逸类漏洞,成因是 runc 在初始化容器进程时泄漏了指向宿主机文件系统的文件描述符。攻击者可在容器内通过 /proc/self/fd 访问该描述符,进而读写宿主机文件或执行命令,实现容器逃逸。

利用条件与风险

利用需要攻击者能够控制容器镜像或容器启动配置(如通过恶意镜像或 Dockerfile 中的 WORKDIR),在共享宿主机内核的容器环境中实战风险较高。

修复建议

官方已在 runc 1.1.12 中修复,建议升级 runc 并更新 Docker、containerd 等依赖组件;临时缓解可避免使用不可信镜像,并限制容器工作目录设置。

原始情报

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem (“attack 2”). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run (“attack 1”). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes (“attack 3a” and “attack 3b”). runc 1.1.12 includes patches for this issue.