{"id":"GO-2024-2491","summary":"Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc","details":"Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc","aliases":["CVE-2024-21626","GHSA-xr7r-f8xq-vfvv"],"modified":"2026-07-17T21:07:58.008074863Z","published":"2024-06-28T15:28:53Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2024-2491","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv"},{"type":"FIX","url":"https://github.com/opencontainers/runc/commit/02120488a4c0fc487d1ed2867e901eeed7ce8ecf"},{"type":"WEB","url":"http://packetstormsecurity.com/files/176993/runc-1.1.11-File-Descriptor-Leak-Privilege-Escalation.html"}],"affected":[{"package":{"name":"github.com/opencontainers/runc","ecosystem":"Go","purl":"pkg:golang/github.com/opencontainers/runc"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0-rc93"},{"fixed":"1.1.12"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/opencontainers/runc/libcontainer/utils","symbols":["CloseExecFrom"]},{"path":"github.com/opencontainers/runc/libcontainer/cgroups","symbols":["openFile","prepareOpenat2"]},{"path":"github.com/opencontainers/runc/libcontainer","symbols":["Container.start","Init","finalizeNamespace","linuxSetnsInit.Init","linuxStandardInit.Init"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-2491.json"}}],"schema_version":"1.7.5","credits":[{"name":"Rory McNamara from Snyk"},{"name":"@lifubang from acmcoder"},{"name":"Aleksa Sarai from SUSE"}]}