GO-2021-0070
Dashboard / Vulnerabilities / GO-2021-0070
Summary: Privilege escalation in github.com/opencontainers/runc
Details: GetExecUser in the github.com/opencontainers/runc/libcontainer/user package will improperly interpret numeric UIDs as usernames. If the method is used without verifying that usernames are formatted as expected, it may allow a user to gain unexpected privileges.
References: https://github.com/opencontainers/runc/pull/708, https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091, https://github.com/docker/docker/issues/21436, http://rhn.redhat.com/errata/RHSA-2016-1034.html, http://rhn.redhat.com/errata/RHSA-2016-2634.html, https://security.gentoo.org/glsa/201612-28
Affected packages
Package
Name: github.com/opencontainers/runc
Purl: pkg:golang/github.com/opencontainers/runc
Affected ranges
Type: SEMVER
Events:
