CVE-2024-21626

Red Hat Security Advisory: OpenShift Container Platform 4.14.49 bug fix and security update

Description

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

Metrics

Severity
high
no public PoC known
8.6
Source: nvd-v3
97.0 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
18.1 %
Elevated — model estimates 10-50% exploitation likelihood.
Published
2025-03-19 20:54 UTC
CWE-403, CWE-668

Weakness classes (CWE)

  • CWE-403Base

    Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')

    A process does not close sensitive file descriptors before invoking a child process, which allows the child to perform unauthorized I/O operations using those descriptors.

    cwe.mitre.org →
  • CWE-668Class

    Exposure of Resource to Wrong Sphere

    The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-24 13:16 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77)OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77)
  2. CVE Modified2026-08-20 13:16 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77)OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77)
  3. CVE Modified2026-08-18 12:16 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77)OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77)
  4. CVE Modified2026-07-20 12:16 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+77)OCP-Tools-4.15-RHEL-8, OCP-Tools-4.15-RHEL-8, Red Hat Enterprise Linux 7 Extras (+76)

Affected operating systems

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_eus8.8

  • linux

    redhat / enterprise_linux_eus9.0

  • linux

    redhat / enterprise_linux_eus9.2

  • linux

    redhat / enterprise_linux_eus9.4

  • linux

    redhat / enterprise_linux_for_arm_648.0_aarch64

  • linux

    redhat / enterprise_linux_for_arm_649.0_aarch64

  • linux

    redhat / enterprise_linux_for_arm_64_eus8.8_aarch64

  • linux

    redhat / enterprise_linux_for_arm_64_eus9.0_aarch64

  • linux

    redhat / enterprise_linux_for_arm_64_eus9.2_aarch64

  • linux

    redhat / enterprise_linux_for_arm_64_eus9.4_aarch64

  • linux

    redhat / enterprise_linux_for_ibm_z_systems8.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus8.8_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.2_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.4_s390x

  • linux

    redhat / enterprise_linux_for_power_little_endian8.0_ppc64le

  • linux

    redhat / enterprise_linux_for_power_little_endian9.0_ppc64le

  • linux

    redhat / enterprise_linux_for_power_little_endian_eus8.8_ppc64le

  • linux

    redhat / enterprise_linux_for_power_little_endian_eus9.0_ppc64le

  • linux

    redhat / enterprise_linux_for_power_little_endian_eus9.2_ppc64le

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • android

    :linux_kernel::0

  • android

    :linux_kernel:Kernel

  • go

    github.com/containers/buildah1.35.0

  • go

    github.com/containers/buildah1.37.0

  • go

    github.com/containers/buildah1.38.0

  • go

    github.com/containers/buildah

  • go

    golang.org/x/net

  • linuxfoundation

    runc1.1.12

References & sources

Linked CVEs

IDCVE-2024-21626