Snyk has discovered a vulnerability in all versions of runc <=1.1.11, as used by the Docker engine, along with other containerization technologies such as Kubernetes. Exploitation of this issue can result in container escape to the underlying host OS, either through executing a malicious image or building an image using a malicious Dockerfile or upstream image (i.e., when using FROM). This issue has been assigned the CVE-2024-21626.
runc runtime was updated to 1.1.12 in Talos v1.5.6 and v1.6.4.
Inspect the workloads running on the cluster to make sure they are not trying to exploit the vulnerability.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2024-02-02T18:11:06Z",
"nvd_published_at": null,
"severity": "HIGH"
}