Language:
https://security.gentoo.org/glsa/202408-25
https://bugs.gentoo.org/show_bug.cgi?id=828471
https://bugs.gentoo.org/show_bug.cgi?id=844085
Severity: High
ID: 205353
File Name: gentoo_GLSA-202408-25.nasl
Version: 1.2
Type: local
Family: Gentoo Local Security Checks
Published: 8/11/2024
Updated: 8/12/2024
Supported Sensors: Nessus
Risk Factor: Critical
Score: 9.2
Risk Factor: Medium
Base Score: 6
Temporal Score: 5
Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:P
CVSS Score Source: CVE-2021-43784
Risk Factor: High
Base Score: 8.6
Temporal Score: 8
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C
CVSS Score Source: CVE-2024-21626
CPE: cpe:/o:gentoo:linux, p-cpe:/a:gentoo:linux:runc
Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 8/11/2024
Vulnerability Publication Date: 12/6/2021
Metasploit (runc (docker) File Descriptor Leak Privilege Escalation)
CVE: CVE-2021-43784, CVE-2022-29162, CVE-2023-25809, CVE-2023-27561, CVE-2023-28642, CVE-2024-21626