Charliecloud is not affected by CVE-2024-21626 or related vulnerabilities
Reid Priedhorsky, USDOE National Nuclear Security Administration (NNSA) · 2024
As you may be aware, four vulnerabilities in popular open-source container implementations were announced on January 21. Nicknamed “Leaky Vessels” by the Snyk Security Labs team that discovered them [1], these vulnerabilities in runC (CVE-2024-21626) and Moby BuildKit (CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653) allow malicious container images or builds to execute arbitrary code on the container host with the privileges of the container runtime, i.e., a “container breakout”. Often, including typical configurations of Docker and/or Kubernetes, that means full root access.