runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. References: https://github.com/opencontainers/runc/security/advisories/GHSA-g2j6-57v7-gm8c https://github.com/opencontainers/runc/pull/3785
Created runc tracking bugs for this issue: Affects: fedora-all [bug 2192149]
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2023:1326 https://access.redhat.com/errata/RHSA-2023:1326
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:6380 https://access.redhat.com/errata/RHSA-2023:6380
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:6938 https://access.redhat.com/errata/RHSA-2023:6938
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:6939 https://access.redhat.com/errata/RHSA-2023:6939
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2024:0564 https://access.redhat.com/errata/RHSA-2024:0564