{"schema_version":"1.7.3","id":"GO-2024-2491","published":"2024-06-28T15:28:53Z","modified":"2026-02-04T02:39:00.262696Z","aliases":["CVE-2024-21626","GHSA-xr7r-f8xq-vfvv"],"related":["CGA-jmjc-ph87-4994"],"summary":"Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc","details":"Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc","affected":[{"package":{"name":"github.com/opencontainers/runc","ecosystem":"Go","purl":"pkg:golang/github.com/opencontainers/runc"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0-rc93"},{"fixed":"1.1.12"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/opencontainers/runc/libcontainer/utils","symbols":["CloseExecFrom"]},{"path":"github.com/opencontainers/runc/libcontainer/cgroups","symbols":["openFile","prepareOpenat2"]},{"path":"github.com/opencontainers/runc/libcontainer","symbols":["Container.start","Init","finalizeNamespace","linuxSetnsInit.Init","linuxStandardInit.Init"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-2491.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv"},{"type":"FIX","url":"https://github.com/opencontainers/runc/commit/02120488a4c0fc487d1ed2867e901eeed7ce8ecf"},{"type":"WEB","url":"http://packetstormsecurity.com/files/176993/runc-1.1.11-File-Descriptor-Leak-Privilege-Escalation.html"}],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2024-2491"},"credits":[{"name":"Rory McNamara from Snyk"},{"name":"@lifubang from acmcoder"},{"name":"Aleksa Sarai from SUSE"}]}