Search/CVE-2021-43784
CVE — Medium

CVE-2021-43784

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used internally as a serialization system for specifying the relevant container configuration to the C portion of the code (responsible for the based namespace setup of containers). In all versions of runc prior to 1.0.3, the encoder did not handle the possibility of an integer overflow in the 16-bit length field for the byte array attribute type, meaning that a large enough malicious byte array attribute could result in the length overflowing and the attribute contents being parsed as netlink messages for container configuration. This vulnerability requires the attacker to have some control over the configuration of the container and would allow the attacker to bypass…

CVSS v3.1
6 MEDIUM
EPSS
1.67%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Aug 18, 2026
0.01pp
1.68% → 1.67% over 2 tracked changes
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
ScopeCHANGED
ConfidentialityLOW
IntegrityLOW
AvailabilityLOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
Connections
3 relationships
Timeline
disclosure → media coverage
Dec 6, 2021
Disclosure — published as a CVE record. · last revised by NVD Nov 21, 2024