Engineering Papers⌕ Search

Engineering topics

Priedhorsky, Reid

Publications and source records attributed to Priedhorsky, Reid.

Charliecloud is not affected by CVE-2024-21626 or related vulnerabilities

As you may be aware, four vulnerabilities in popular open-source container implementations were announced on January 21. Nicknamed “Leaky Vessels” by the Snyk Security Labs team that discovered them [1], these vulnerabilities in runC (CVE-2024-21626) and Moby BuildKit (CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653) allow malicious container images or builds to execute arbitrary code on the container host with the privileges of the container runtime, i.e., a “container breakout”. Often, including typical configurations of Docker and/or Kubernetes, that means full root access.

97 MATHEMATICS AND COMPUTING↗

Charliecloud 101

This workshop will provide participants with background and hands-on experience to use basic containers for HPC applications. We will discuss what containers are, why they matter for HPC, and how they work. We’ll give an overview of Charliecloud, the unprivileged container solution from HPC Division, and walk participants through installing it on their own compute resource. Participants will build toy containers and a real HPC application, and then run them in parallel on an HPC Division cluster. This will be a highly interactive workshop with lots of Q&A.

97 MATHEMATICS AND COMPUTING↗