VendorsLinux Foundationruncall versions
Vulnerabilities

Linux Foundation Runc

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
Published 2019-02-11 · Modified
9.32 PoCEPSS 0.985
CVE-2024-21626
runc container breakout through process.cwd trickery and leaked fds
Published 2024-01-31 · Modified
8.6EPSS 0.181
CVE-2021-30465
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.
Published 2021-05-27 · Modified
8.5EPSS 0.066
CVE-2025-52565
container escape due to /dev/console mount and related races
Published 2025-11-06 · Analyzed
8.4EPSS 0.006
CVE-2025-31133
runc container escape via "masked path" abuse due to mount race conditions
Published 2025-11-06 · Analyzed
7.8EPSS 0.008
CVE-2022-29162
Incorrect Default Permissions in runc
Published 2022-05-17 · Modified
7.8EPSS 0.004
CVE-2016-3697
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
Published 2016-06-01 · Modified
7.8EPSS 0.004
CVE-2023-28642
AppArmor bypass with symlinked /proc in runc
Published 2023-03-29 · Modified
7.8EPSS 0.003
CVE-2019-16884
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
Published 2019-09-25 · Modified
7.5EPSS 0.044
CVE-2025-52881
runc: LSM labels can be bypassed with malicious config using dummy procfs files
Published 2025-11-06 · Analyzed
7.5EPSS 0.006
CVE-2023-27561
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
Published 2023-03-03 · Modified
7.0EPSS 0.004
CVE-2019-19921
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)
Published 2020-02-12 · Modified
7.0EPSS 0.004
CVE-2023-25809
rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runc
Published 2023-03-29 · Modified
6.3EPSS 0.003
CVE-2021-43784
Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration
Published 2021-12-06 · Modified
6.0EPSS 0.017
CVE-2022-24769
Default inheritable capabilities for linux container should be empty
Published 2022-03-24 · Modified
5.9EPSS 0.005
CVE-2024-45310
runc can be confused to create empty files/directories on the host
Published 2024-09-03 · Analyzed
3.6EPSS 0.003
CVE-2026-41579
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
Published 2026-07-01 · Analyzed
3.3EPSS 0.002