Database/Container, Kubernetes & orchestration
runc: Volume-mount race gives incorrect access control and privilege escalation to host
CVE-2019-19921Container, Kubernetes & orchestrationcurated
Impact
Volume-mount race gives incorrect access control and privilege escalation to host
Who can reach it
Any tenant workload able to spawn two containers with crafted mounts
What to do
Replace runc binary; drain node
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.