CVE-2023-27561: Debian Linux
High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
Affected products
- Debian Debian Linux: version 10.0 only
- Linuxfoundation Runc: before 1.1.5 (fixed in 1.1.5)
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
- Red Hat Openshift Container Platform: version 4.0 only
Published 2023-03-03. Last modified 2026-06-17.