Runc vulnerability CVE-2024-21626 allowing container escape in all Docker and Kubernetes environments

Open link in next tab

Docker Security Advisory: Multiple Vulnerabilities in runc, BuildKit, and Moby

https://www.docker.com/blog/docker-security-advisory-multiple-vulnerabilities-in-runc-buildkit-and-moby/

Docker security advisory about multiple vulnerabilities in runc, BuildKit, and Moby: We will publish patched versions of runc, BuildKit, and Moby on January 31 and release an update for Docker Desktop on February 1 to address these vulnerabilities.  Additionally, our latest Moby and BuildKit releases will include fixes for CVE-2024-23650 and CVE-2024-24557, discovered respectively by an independent researcher and through Docker’s internal research initiatives.

Docker Security Advisory: Multiple Vulnerabilities in runc, BuildKit, and Moby

Seems like a really serious vulnerability, any container attack or malicious image could take over a container host if there's no hardening on the containers.