logo

Leaky Vessels: runC and BuildKit container escape vulnerabilities - everything you need to know

ID: 163a492a-9360-5e42-a0c0-69f7320128ee

STIX ID: report--163a492a-9360-5e42-a0c0-69f7320128ee

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2024-02-05

Date Updated: 2026-05-01

...
...

Wiz Research details “Leaky Vessels,” four container escape vulnerabilities—CVE-2024-21626 (runC) and CVE-2024-23651/23652/23653 (BuildKit)—that can enable host filesystem access and privileged host compromise via malicious Dockerfiles, BuildKit frontends, or runc exec. The advisory lists affected versions, available patches (runC v1.1.12; BuildKit v0.12.5; Moby/Docker Engine v25.0.2; Docker Desktop v4.27.1), prioritized remediation guidance for cloud/container operators, and detection/prevention options including the Wiz Runtime Sensor and Threat Center queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.