Illustrate runC Escape Vulnerability CVE-2024–21626 with my tests

Bill WANG
Towards Dev
Published in
5 min readFeb 7, 2024

--

CVE-2024–21626

The vulnerability CVE-2024–21626 allows an attacker to escape containers

For runC, a container runtime component, published version 1.1.12 to fix CVE-2024-21626 at 31, Jan 2024, which leads to escaping from containers. The range of affected versions are >= v1.0.0-rc93, <=1.1.11.

For containerd, the fixed versions are 1.6.28 and 1.7.13, the range of affected versions are 1.4.7 to 1.6.27 and 1.7.0 to 1.7.12.

--

--