Package
virt-controller-1.8
Component
github.com/opencontainers/runc
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
This vulnerability only applies when runc executes containers via libcontainer.Container, where maskedPaths mount setup is raced during container init. KubeVirt does not invoke runc as a container runtime — it links only runc's libcontainer/cgroups subpackages for host-side cgroup management and never reaches the vulnerable mount-namespace setup code. Reference: upstream kubevirt closed every release-branch runc bump PR (e.g. https://github.com/kubevirt/kubevirt/pull/16928) with the maintainer determination "I reviewed the CVE mentioned, I believe we are not affected".
Status