AWS-2024-001
Scope: AWS Content Type: Important (requires attention) Publication Date: 2024/01/31 1:30 PM PST CVE Identifier: CVE-2024-21626 AWS is aware of a recently disclosed security issue affecting the runc component of several open source container management systems (CVE-2024-21626). With the exception of the AWS services listed below, no customer action is required to address this issue. Amazon Linux An updated version of runc is available for Amazon Linux 1 (runc-1.1.11-1.0.amzn1), Amazon Linux 2 (runc-1.1.11-1.amzn2) and for Amazon Linux 2023 (runc-1.1.11-1.amzn2023). AWS recommends that customers using runc or other container-related software apply those updates or a newer version. Further information is available in the Amazon Linux Security Center . Bottlerocket OS An updated version of runc will be included in Bottlerocket 1.19.0, which will be released by February 2, 2024. AWS recommends that customers using Bottlerocket apply this update or a newer version. Further information will be posted in the Bottlerocket Security Advisories and the Bottlerocket Release Notes . Amazon Elastic Container Service (ECS) This CVE has been patched in runc, and an updated version of runc, version…
Timeline
- Jan 31, 2024 CVE Published
References
- CVE-2024-21626 - Runc container issue advisory
- https://alas.aws.amazon.com/cve/html/CVE-2024-21626.html web
- https://github.com/bottlerocket-os/bottlerocket/security/advisories web
- https://github.com/bottlerocket-os/bottlerocket/releases web
- https://github.com/aws/amazon-ecs-ami/releases web
- https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html web
- https://docs.aws.amazon.com/eks/latest/userguide/update-managed-node-group.html web
- https://karpenter.sh/docs/concepts/disruption/#drift web
- https://karpenter.sh/docs/concepts/nodeclasses/#specamiselectorterms web
- https://docs.aws.amazon.com/eks/latest/userguide/update-workers.html web
- https://docs.aws.amazon.com/eks/latest/userguide/fargate-getting-started.html web
- https://github.com/aws/eks-anywhere/releases/tag/v0.18.6 patch
- https://anywhere.eks.amazonaws.com/docs/clustermgmt/cluster-upgrades/ web
- http://docs.aws.amazon.com/elasticbeanstalk/latest/dg/environment-platform-update-managed.html web
- https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/using-features.platform.upgrade.html web
- https://github.com/runfinch/finch/releases web
- https://docs.aws.amazon.com/batch/latest/userguide/compute_environments.html#managed_compute_environments web
- https://docs.aws.amazon.com/batch/latest/userguide/create-batch-ami.html web