CVE-2024-45310 is a low-severity vulnerability in runc, a container runtime, affecting versions 1.1.13 and earlier, and 1.2.0-rc2 and earlier, including its use in Docker and Kubernetes. It allows an attacker with the ability to configure custom volumes to create empty files or directories in arbitrary host filesystem locations by exploiting a race condition during volume sharing. The attack requires user interaction (UI:R) and has a low impact, primarily affecting integrity (I:L) by creating empty files without truncating existing ones. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.14CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:* | ||
1.2.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:1.2.0:rc1:*:*:*:*:*:* | ||
1.2.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:1.2.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
runc can be confused to create empty files/directories on the host
Sep 10, 2024runc can be confused to create empty files/directories on the host
Sep 3, 2024runc: runc can be tricked into creating empty files/directories on host
Sep 3, 2024