CVE-2021-30465 is a high-severity directory traversal vulnerability in runc versions prior to 1.0.0-rc95, affecting products like Fedora. It allows a container filesystem breakout through a symlink-exchange race condition, requiring an attacker to create multiple containers with specific mount configurations. The attack complexity is high, but successful exploitation could lead to complete compromise of confidentiality, integrity, and availability. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been observed, there has been some community discussion, including a detailed write-up.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.1.1CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:1.0.0:rc1:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:1.0.0:rc10:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:1.0.0:rc2:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:1.0.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Runc container escape vulnerability (CVE-2021-30465)
Oct 19, 2021runc filesystem access vulnerability (CVE-2021-30465)
Oct 19, 2021mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs
May 25, 2021runc: vulnerable to symlink exchange attack
May 19, 2021