
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-30465 affects runc versions before 1.0.0-rc95, allowing a Container Filesystem Breakout via Directory Traversal. The vulnerability was discovered and disclosed on May 19, 2021. The issue affects runc, which is a core component of all OCI compliant container runtimes and is used in various container platforms including Docker and Kubernetes (GitHub Advisory, NVD).
The vulnerability stems from a symlink-exchange attack that exploits a time-of-check-to-time-of-use (TOCTTOU) race condition. An attacker can trick runc into mounting outside of the container rootfs by swapping the target of a mount with a symlink. While this occurs inside a mount namespace with MS_SLAVE propagation, the attack becomes effective when combined with additional mount entries that use a subpath of the mounted-over host path as a source for subsequent mounts. The vulnerability has been assigned a CVSS v3.1 base score of 8.5 (HIGH) with vector AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H (GitHub Advisory, NVD).
If successfully exploited, this vulnerability allows an attacker to break out of the container and gain access to the host filesystem. In Kubernetes environments, an attacker can create a symlink in a volume to the top-level directory where volumes are sourced from, and subsequently gain access to the host system. The impact is particularly severe in multi-tenant environments where containers share volumes (GitHub Advisory, Red Hat Blog).
To exploit this vulnerability, an attacker must have the ability to create multiple containers with specific mount configurations and be able to run malicious code in a container that shares volumes with said configuration. The attack is facilitated when host paths used for volume management are well-known. While security mechanisms like LSMs (AppArmor/SELinux) and user namespaces can restrict the damage, they do not completely block the attack (GitHub Advisory).
The vulnerability was fixed in runc version 1.0.0-rc95. Users are strongly recommended to upgrade to this version or later. While there are no direct workarounds, implementing strict security profiles can help restrict potential damage. This includes using reduced capabilities, avoiding root execution in containers, enabling user namespaces, AppArmor/SELinux, and seccomp. SELinux in enforcing mode particularly helps mitigate the impact by preventing access to files or sockets not allowed by the SELinux label (Red Hat Blog, GitHub Advisory).
Fix availability across major Linux distributions and their releases.
edge
k3s: 1.21.1.1-r0, 1.0.0_rc95-r0
v3.18
k3s: 1.21.1.1-r0, 1.0.0_rc95-r0
v3.19
k3s: 1.21.1.1-r0, 1.0.0_rc95-r0
v3.20
k3s: 1.21.1.1-r0, 1.0.0_rc95-r0
v3.21
k3s: 1.21.1.1-r0, 1.0.0_rc95-r0
v3.22
k3s: 1.21.1.1-r0, 1.0.0_rc95-r0
v3.23
k3s: 1.21.1.1-r0, 1.0.0_rc95-r0
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."