runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
CVE ID: CVE-2023-27561
CVSS Base Severity: LOW
CVSS Base Score: 0.0
Vendor: n/a
Product: n/a
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 25.34% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)