CVE-2023-28642 is a high-severity vulnerability affecting runc, a CLI tool for container management, where AppArmor security policies can be bypassed. This bypass occurs when the /proc directory within a container is symlinked with a specific mount configuration, potentially allowing an attacker to escape container isolation. The vulnerability has a CVSS score of 7.8, indicating a local attack vector with low complexity, leading to high impacts on confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, users are strongly advised to upgrade to runc version 1.1.5 or later, or avoid using untrusted container images.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.5CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-28642
Apr 11, 2023runc AppArmor bypass with symlinked /proc
Mar 30, 2023runc: AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration
Mar 29, 2023AppArmor bypass with symlinked /proc in runc
Mar 14, 2023