Skip to content

Does CVE-2024-21626 only affect systems that support openat2? #4184

Closed Answered by cyphar
payall4u asked this question in Q&A
Discussion options

You must be logged in to vote

There were several other internal fd leaks we fixed, as well as adding hardening that will ensure future fd leaks won't cause issues in the future. In addition, runc 1.1.4 is also vulnerable to three different CVEs that we fixed in 1.1.5 (CVE-2023-25809, CVE-2023-27561, CVE-2023-28642). I would strongly suggest that you always upgrade to the latest version of runc as soon as possible, because we do not provide support for older versions.

Closing, since I believe your question has been answered.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
2 replies
@vsxen
Comment options

@lifubang
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by payall4u
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants