'Leaky Vessels' Cloud Bugs Allow Container Escapes Globally
ID: e0ec4627-33d3-57d4-a5fd-4f25b4f5c5f1
STIX ID: report--e0ec4627-33d3-57d4-a5fd-4f25b4f5c5f1
Feed Name: Dark Reading
Researchers at Snyk disclosed four "Leaky Vessels" vulnerabilities affecting container runtimes and build tooling — notably runC (CVE-2024-21626, CVSS 8.6) and three BuildKit flaws (CVE-2024-23651, CVE-2024-23653, CVE-2024-23652) — that can enable container escape and arbitrary host file deletion; the issues are easy to exploit given local build/run access but require the ability to run or build containers on the target, and organizations are urged to apply vendor fixes promptly due to the widespread use of these components.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
