High SEVERITY — Vulnerability

runc CVE-2024-21626: LXC container escape patch

A runtime container vulnerability can allow access to the host filesystem; the patched version in the PVE repositories should be installed.

Platform
Proxmox VE
Version
PVE 8 / Bookworm tabanlı
CVE Record
CVE-2024-21626
CVSS Score
8.6/10
Published
01 February 2026
Views
4
Primary source: Review the official advisory at forum.proxmox.com Kaynağa Git

Özet

CVE-2024-21626, runc's WORKDIR handling bug allows escaping from a container to the host filesystem. The direct impact on PVE is limited because the LXC infrastructure in PVE does not use runc; however, the risk is high for VMs and CTs running nested Docker/Podman.

Aksiyon

  • Use apt dist-upgrade to install up-to-date kernel and userland packages
  • Update CT templates that run Docker
  • If possible, move containers to unprivileged mode

Proxmox VE — Related Advisories

VIEW ALL →