CVE-2024-21626
Red Hat Security Advisory: OpenShift Container Platform 4.14.49 bug fix and security update
Description
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.
Metrics
Weakness classes (CWE)
CWE-403Base
Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')
A process does not close sensitive file descriptors before invoking a child process, which allows the child to perform unauthorized I/O operations using those descriptors.
cwe.mitre.org →CWE-668Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-08-24 13:16 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77) → OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77)
- CVE Modified2026-08-20 13:16 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77) → OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77)
- CVE Modified2026-08-18 12:16 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77) → OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77)
- CVE Modified2026-07-20 12:16 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77) → OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+76)
Affected operating systems
linux
debian / debian_linux11.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux9.0
linux
redhat / enterprise_linux_eus8.8
linux
redhat / enterprise_linux_eus9.0
linux
redhat / enterprise_linux_eus9.2
linux
redhat / enterprise_linux_eus9.4
linux
redhat / enterprise_linux_for_arm_648.0_aarch64
linux
redhat / enterprise_linux_for_arm_649.0_aarch64
linux
redhat / enterprise_linux_for_arm_64_eus8.8_aarch64
linux
redhat / enterprise_linux_for_arm_64_eus9.0_aarch64
linux
redhat / enterprise_linux_for_arm_64_eus9.2_aarch64
linux
redhat / enterprise_linux_for_arm_64_eus9.4_aarch64
linux
redhat / enterprise_linux_for_ibm_z_systems8.0_s390x
linux
redhat / enterprise_linux_for_ibm_z_systems9.0_s390x
linux
redhat / enterprise_linux_for_ibm_z_systems_eus8.8_s390x
linux
redhat / enterprise_linux_for_ibm_z_systems_eus9.0_s390x
linux
redhat / enterprise_linux_for_ibm_z_systems_eus9.2_s390x
linux
redhat / enterprise_linux_for_ibm_z_systems_eus9.4_s390x
linux
redhat / enterprise_linux_for_power_little_endian8.0_ppc64le
linux
redhat / enterprise_linux_for_power_little_endian9.0_ppc64le
linux
redhat / enterprise_linux_for_power_little_endian_eus8.8_ppc64le
linux
redhat / enterprise_linux_for_power_little_endian_eus9.0_ppc64le
linux
redhat / enterprise_linux_for_power_little_endian_eus9.2_ppc64le
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
android
:linux_kernel::0
android
:linux_kernel:Kernel
go
github.com/containers/buildah1.35.0
go
github.com/containers/buildah1.37.0
go
github.com/containers/buildah1.38.0
go
github.com/containers/buildah
go
golang.org/x/net
linuxfoundation
runc1.1.12
References & sources
- https://source.android.com/security/bulletin/2025-03-01advisory
- https://android.googlesource.com/kernel/common/+/f02dd268a08d4e7ec09ec0ddd2a861ab5a51a0aefix
- https://android.googlesource.com/kernel/common/+/853ec04e2de45ae6d1fc9476ce52d06582ad87edfix
- https://git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26
- https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5
- https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46
- https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf
- https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b
- https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191
- https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648
- https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-50302government-resource
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-355557.html
- https://go.dev/cl/637536fix
- https://go.dev/issue/70906report
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJweb
- https://pkg.go.dev/vuln/GO-2024-3333
Linked CVEs
- CVE-2024-9676
A vulnerability was found in Podman, Buildah, and CRI-O.
mediumCVSSv3 6.5 - CVE-2024-9675
A vulnerability was found in Buildah.
highCVSSv3 7.8 - CVE-2024-53197Actively exploited
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and…
criticalCVSSv3 7.8 - CVE-2024-50302Actively exploited
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffe…
criticalCVSSv3 5.5 - CVE-2024-45338
A flaw was found in golang.org/x/net/html.
— - CVE-2024-11218
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race conditi…
highCVSSv3 8.6 - CVE-2024-11187
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional sec…
highCVSSv3 7.5