CVE-2021-43784

medium
Published 2023-11-07 · Modified 2023-11-14
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
CVSS v2
VIR risk
5.5

Description

Moderate: runc security update

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6380.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2182884

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2182883

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2178492

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2175721

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2029439

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-43784

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6380

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
arch archfixed1.0.3-1
debian debianbookwormfixed1.0.3+ds1-1
debian debianbullseyefixed1.0.0~rc93+ds1-5+deb11u4
debian debianforkyfixed1.0.3+ds1-1
debian debiansidfixed1.0.3+ds1-1
debian debiantrixiefixed1.0.3+ds1-1

Package impact

EcosystemPackageVulnerableFixed
golang Gogithub.com/opencontainers/runc<1.0.31.0.3
golang Gogithub.com/opencontainers/runc>=1.0.1-0.20211012131345-9c444070ec7b,<1.1.01.1.0

References

Verify integrity in audit chain (admin only). AS-IS.