GPU VulnDB

Database/Container, Kubernetes & orchestration

runc: runc can be tricked into creating empty files/directories at arbitrary host locations

CVE-2024-45310Container, Kubernetes & orchestrationcurated

Impact

runc can be tricked into creating empty files/directories at arbitrary host locations

Who can reach it

Any tenant workload with control over the pod's mount config

What to do

Replace runc binary; drain node

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.