Vulnerability Name:

CVE-2023-28642 (CCN-251539)

Assigned:2023-03-29
Published:2023-03-29
Updated:2023-04-06
Summary:runc could allow a remote attacker to bypass security restrictions, caused by a symbolic link following vulnerability. By creating a symbolic link inside a container to the /proc directory, an attacker could exploit this vulnerability to bypass AppArmor and SELinux protections.
CVSS v3 Severity:6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L)
5.3 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
6.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L)
5.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2023-28642

Source: XF
Type: UNKNOWN
runc-cve202328642-sec-bypass(251539)

Source: security-advisories@github.com
Type: Patch
security-advisories@github.com

Source: CCN
Type: runc GIT Repository
AppArmor/SELinux bypass with symlinked /proc

Source: security-advisories@github.com
Type: Patch, Vendor Advisory
security-advisories@github.com

Source: CCN
Type: IBM Security Bulletin 6999699 (Cloud Pak for Watson AIOps)
Multiple Vulnerabilities in CloudPak for Watson AIOPs

Source: CCN
Type: IBM Security Bulletin 6999781 (Edge Application Manager)
IBM Edge Application Manager 4.5.1 addresses multiple security vulnerabilities

Source: CCN
Type: IBM Security Bulletin 7016688 (MQ Operator)
IBM MQ Operator and Queue manager container images are vulnerable to multiple vulnerabilities from openssl-libs, libssh, libarchive, sqlite and go-toolset

Oval Definitions
Definition IDClassTitleLast Modified
oval:org.opensuse.security:def:7865
P
runc-1.1.5-150000.41.1 on GA media (Moderate)
2023-06-12
oval:org.opensuse.security:def:55536
P
Security update for runc (Important) (in QA)
2023-04-03
BACK