runc: Execution of malicious containers allows for container escape and access to host filesystem
Published Feb 11, 2019
8.6
HIGHCVSS 3.1
EPSS 98.45%
Description
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
Affected products
No data.
Configuration 2
- ≤ 0.1.1
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.0
Configuration 3
- 3.7
- 3.4
- 3.5
- 3.6
- 3.7
- 8.0
- 7.0
Configuration 4
- n/a
Configuration 5
- < 3.2.0
Configuration 7
- n/a
- n/a
Configuration 8
Configuration 9
- 15.0
- 15.0
- 15.0
- 15.1
- 42.3
Configuration 10
Configuration 11
- 29
- 30
Configuration 12
- 16.04
- 18.04
- 18.10
- 19.04
Configuration 13
- 2018.02
- 2018.05
- 2018.08
- 2018.11
No data.
Other
n/a
Fixed · RHSA-2019:0401
Red Hat Enterprise Linux 7 Extras
docker-2:1.13.1-91.git07f3374.el7
Fixed · RHSA-2019:0304
Red Hat Enterprise Linux 7 Extras
runc-0:1.0.0-59.dev.git2abd837.el7
Fixed · RHSA-2019:0303
Red Hat Enterprise Linux 8
container-tools:rhel8-8000020190416221845.2ffa3d27
Fixed · RHSA-2019:0975
Red Hat OpenShift Container Platform 3.4
docker-2:1.12.6-79.git5680db5.el7
Fixed · RHSA-2019:0408
Red Hat OpenShift Container Platform 3.5
docker-2:1.12.6-79.git5680db5.el7
Fixed · RHSA-2019:0408
Red Hat OpenShift Container Platform 3.6
docker-2:1.12.6-79.git5680db5.el7
Fixed · RHSA-2019:0408
Red Hat OpenShift Container Platform 3.7
docker-2:1.12.6-79.git5680db5.el7
Fixed · RHSA-2019:0408
Red Hat Enterprise Linux 7
docker-latest
Will not fix
Red Hat Enterprise Linux 8
container-tools:1.0/runc
Not affected
Red Hat Enterprise Linux Atomic Host 7
docker
Not affected
Red Hat Enterprise Linux Atomic Host 7
runc
Not affected
Red Hat OpenShift Container Platform 3.9
runc
Will not fix
Red Hat OpenShift Container Platform 4
runc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Other | n/a | Fixed | RHSA-2019:0401 |
| Red Hat Enterprise Linux 7 Extras | docker-2:1.13.1-91.git07f3374.el7 | Fixed | RHSA-2019:0304 |
| Red Hat Enterprise Linux 7 Extras | runc-0:1.0.0-59.dev.git2abd837.el7 | Fixed | RHSA-2019:0303 |
| Red Hat Enterprise Linux 8 | container-tools:rhel8-8000020190416221845.2ffa3d27 | Fixed | RHSA-2019:0975 |
| Red Hat OpenShift Container Platform 3.4 | docker-2:1.12.6-79.git5680db5.el7 | Fixed | RHSA-2019:0408 |
| Red Hat OpenShift Container Platform 3.5 | docker-2:1.12.6-79.git5680db5.el7 | Fixed | RHSA-2019:0408 |
| Red Hat OpenShift Container Platform 3.6 | docker-2:1.12.6-79.git5680db5.el7 | Fixed | RHSA-2019:0408 |
| Red Hat OpenShift Container Platform 3.7 | docker-2:1.12.6-79.git5680db5.el7 | Fixed | RHSA-2019:0408 |
| Red Hat Enterprise Linux 7 | docker-latest | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | container-tools:1.0/runc | Not affected | n/a |
| Red Hat Enterprise Linux Atomic Host 7 | docker | Not affected | n/a |
| Red Hat Enterprise Linux Atomic Host 7 | runc | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | runc | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | runc | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The 'docker' package shipped in Red Hat Enterprise Linux 7 Extras bundles 'runc' since 'docker' starting from version 1.12. Both the 'docker' and 'runc' packages are affected by this issue. The 'docker-latest' package is deprecated as of Red Hat Enterprise Linux 7.5. Customers using this package should update to the latest 'docker' package shipped in Red Hat Enterprise Linux 7 Extras. OpenShift Container Platform (OCP) versions 3.9 and later use 'docker' version 1.13 in the default configuration but can be configured to use CRI-O as an alternative, which depends on the 'runc' package. OCP versions 3.9 and later should use the updated 'docker' and 'runc' packages shipped in Red Hat Enterprise Linux 7 Extras. OCP versions 3.4 through 3.7 originally used 'docker' version 1.12 from the Red Hat Enterprise Linux 7 Extras channel. An updated version of 'docker' 1.12 has been delivered to the RPM channels for OCP versions 3.4 through 3.7. OCP version 3.9 previously shipped a version of 'runc' in it's RPM repository. OCP 3.9 clusters using CRI-O should update 'runc' from the Red Hat Enterprise Linux 7 Extras channel. Red Hat Enterprise Linux Atomic Host 7 is not affected by this vulnerability as the target runc binaries are stored on a read-only filesystem and cannot be overwritten.
Red Hat mitigation
This vulnerability is mitigated on Red Hat Enterprise Linux 7 if SELinux is in enforcing mode. SELinux in enforcing mode is a pre-requisite for OpenShift Container Platform 3.x.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (85 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 98.45% (0.98452) | 99.92th | v5 (v2026.06.15) |
| Jun 23, 2026 | 98.57% (0.98570) | 99.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 95.89% (0.95890) | 99.87th | v5 (v2026.06.15) |
| Jun 11, 2026 | 59.18% (0.59178) | 98.27th | v4 (v2025.03.14) |
| Jun 8, 2026 | 55.30% (0.55296) | 98.11th | v4 (v2025.03.14) |
| May 24, 2026 | 59.18% (0.59178) | 98.26th | v4 (v2025.03.14) |
| May 22, 2026 | 61.05% (0.61045) | 98.33th | v4 (v2025.03.14) |
| May 19, 2026 | 55.30% (0.55296) | 98.09th | v4 (v2025.03.14) |
| Apr 21, 2026 | 59.18% (0.59178) | 98.24th | v4 (v2025.03.14) |
| Apr 17, 2026 | 55.30% (0.55296) | 98.08th | v4 (v2025.03.14) |
| Apr 5, 2026 | 59.18% (0.59178) | 98.23th | v4 (v2025.03.14) |
| Apr 1, 2026 | 55.30% (0.55296) | 98.05th | v4 (v2025.03.14) |
| Mar 22, 2026 | 59.18% (0.59178) | 98.21th | v4 (v2025.03.14) |
| Mar 21, 2026 | 61.05% (0.61045) | 98.28th | v4 (v2025.03.14) |
| Mar 7, 2026 | 59.18% (0.59178) | 98.20th | v4 (v2025.03.14) |
| Mar 4, 2026 | 55.30% (0.55296) | 98.01th | v4 (v2025.03.14) |
| Mar 2, 2026 | 49.06% (0.49057) | 97.72th | v4 (v2025.03.14) |
| Mar 1, 2026 | 53.16% (0.53159) | 97.92th | v4 (v2025.03.14) |
| Feb 26, 2026 | 59.18% (0.59178) | 98.19th | v4 (v2025.03.14) |
| Feb 4, 2026 | 55.56% (0.55565) | 98.00th | v4 (v2025.03.14) |
| Feb 1, 2026 | 49.06% (0.49057) | 97.70th | v4 (v2025.03.14) |
| Jan 4, 2026 | 55.56% (0.55565) | 97.98th | v4 (v2025.03.14) |
| Jan 1, 2026 | 49.34% (0.49338) | 97.69th | v4 (v2025.03.14) |
| Dec 28, 2025 | 55.56% (0.55565) | 97.97th | v4 (v2025.03.14) |
| Dec 27, 2025 | 51.04% (0.51040) | 97.77th | v4 (v2025.03.14) |
| Dec 4, 2025 | 55.56% (0.55565) | 97.95th | v4 (v2025.03.14) |
| Dec 1, 2025 | 49.34% (0.49338) | 97.66th | v4 (v2025.03.14) |
| Nov 27, 2025 | 55.56% (0.55565) | 97.95th | v4 (v2025.03.14) |
| Nov 21, 2025 | 58.51% (0.58515) | 98.10th | v4 (v2025.03.14) |
| Nov 18, 2025 | 29.48% (0.29483) | 96.33th | v4 (v2025.03.14) |
| Nov 6, 2025 | 58.26% (0.58255) | 98.08th | v4 (v2025.03.14) |
| Nov 4, 2025 | 55.62% (0.55620) | 97.96th | v4 (v2025.03.14) |
| Nov 1, 2025 | 49.40% (0.49396) | 97.67th | v4 (v2025.03.14) |
| Oct 28, 2025 | 55.62% (0.55620) | 97.95th | v4 (v2025.03.14) |
| Oct 27, 2025 | 51.10% (0.51097) | 97.73th | v4 (v2025.03.14) |
| Oct 13, 2025 | 55.62% (0.55620) | 97.94th | v4 (v2025.03.14) |
| Oct 12, 2025 | 59.49% (0.59487) | 98.13th | v4 (v2025.03.14) |
| Oct 4, 2025 | 53.41% (0.53407) | 97.89th | v4 (v2025.03.14) |
| Oct 1, 2025 | 47.09% (0.47095) | 97.61th | v4 (v2025.03.14) |
| Sep 4, 2025 | 48.81% (0.48812) | 97.69th | v4 (v2025.03.14) |
| Sep 1, 2025 | 42.41% (0.42413) | 97.39th | v4 (v2025.03.14) |
| Aug 30, 2025 | 48.81% (0.48812) | 97.68th | v4 (v2025.03.14) |
| Aug 4, 2025 | 50.73% (0.50726) | 97.75th | v4 (v2025.03.14) |
| Aug 1, 2025 | 44.35% (0.44348) | 97.47th | v4 (v2025.03.14) |
| Jul 30, 2025 | 50.73% (0.50726) | 97.75th | v4 (v2025.03.14) |
| Jul 4, 2025 | 55.26% (0.55263) | 97.91th | v4 (v2025.03.14) |
| Jul 1, 2025 | 49.02% (0.49022) | 97.65th | v4 (v2025.03.14) |
| Jun 28, 2025 | 55.53% (0.55532) | 97.92th | v4 (v2025.03.14) |
| Jun 4, 2025 | 52.48% (0.52476) | 97.77th | v4 (v2025.03.14) |
| Jun 1, 2025 | 46.13% (0.46135) | 97.50th | v4 (v2025.03.14) |
| May 18, 2025 | 52.48% (0.52476) | 97.77th | v4 (v2025.03.14) |
| May 4, 2025 | 55.52% (0.55518) | 97.91th | v4 (v2025.03.14) |
| May 1, 2025 | 49.29% (0.49289) | 97.63th | v4 (v2025.03.14) |
| Mar 23, 2025 | 55.25% (0.55249) | 97.78th | v4 (v2025.03.14) |
| Mar 20, 2025 | 52.61% (0.52607) | 97.74th | v4 (v2025.03.14) |
| Mar 19, 2025 | 55.25% (0.55249) | 97.78th | v4 (v2025.03.14) |
| Mar 17, 2025 | 52.61% (0.52607) | 97.68th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.43% (0.00427) | 75.21th | v3 (v2023.03.01) |
| May 22, 2024 | 0.40% (0.00395) | 73.43th | v3 (v2023.03.01) |
| May 5, 2024 | 0.42% (0.00417) | 73.99th | v3 (v2023.03.01) |
| Feb 23, 2024 | 0.44% (0.00442) | 74.22th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.35% (0.00347) | 70.87th | v3 (v2023.03.01) |
| Jan 21, 2024 | 0.31% (0.00307) | 66.78th | v3 (v2023.03.01) |
| Jan 3, 2024 | 0.26% (0.00264) | 64.01th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.30% (0.00304) | 66.31th | v3 (v2023.03.01) |
| Oct 29, 2023 | 0.30% (0.00298) | 65.97th | v3 (v2023.03.01) |
| Sep 27, 2023 | 0.31% (0.00306) | 66.27th | v3 (v2023.03.01) |
| Aug 25, 2023 | 0.32% (0.00320) | 66.77th | v3 (v2023.03.01) |
| Jul 25, 2023 | 0.35% (0.00347) | 67.91th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.31% (0.00307) | 65.75th | v3 (v2023.03.01) |
| Jun 25, 2023 | 0.39% (0.00393) | 69.67th | v3 (v2023.03.01) |
| Jun 7, 2023 | 0.41% (0.00414) | 70.36th | v3 (v2023.03.01) |
| May 9, 2023 | 0.46% (0.00460) | 71.66th | v3 (v2023.03.01) |
| Apr 8, 2023 | 0.53% (0.00531) | 73.63th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.40% (0.00401) | 69.51th | v3 (v2023.03.01) |
| Mar 6, 2023 | 68.37% (0.68367) | 99.12th | v2 (v2022.01.01) |
| Feb 4, 2022 | 68.37% (0.68367) | 98.94th | v2 (v2022.01.01) |
| Feb 3, 2022 | 96.64% (0.96642) | 100.00th | v1 |
| Dec 9, 2021 | 96.64% (0.96642) | 100.00th | v1 |
| Sep 16, 2021 | 96.59% (0.96591) | 100.00th | v1 |
| Sep 14, 2021 | 79.32% (0.79318) | 99.94th | v1 |
| Sep 1, 2021 | 96.59% (0.96591) | 100.00th | v1 |
| Jul 2, 2021 | 96.59% (0.96591) | 0.00th | v1 |
| Jul 1, 2021 | 96.54% (0.96539) | 0.00th | v1 |
| Apr 14, 2021 | 79.06% (0.79056) | 0.00th | v1 |
References (71)
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00044.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00074.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00091.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00060.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00011.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00015.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00007.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00029.html vendor-advisoryMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/163339/Docker-Container-Escape.html ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/165197/Docker-runc-Command-Execution-Proof-Of-Concept.html Third Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2019/03/23/1 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/28/2 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/3 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/07/06/4 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/24/1 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/29/3 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2024/01/31/6 mailing-list
- http://www.openwall.com/lists/oss-security/2024/02/01/1 mailing-list
- http://www.openwall.com/lists/oss-security/2024/02/02/3 mailing-list
- http://www.securityfocus.com/bid/106976 vdb-entryThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:0303 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0304 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0401 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0408 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0975 vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-5736 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2019-5736 Third Party Advisory
- https://access.redhat.com/security/vulnerabilities/runcescape Third Party Advisory
- https://aws.amazon.com/security/security-bulletins/AWS-2019-002/ Third Party Advisory
- https://azure.microsoft.com/en-us/updates/cve-2019-5736-and-runc-vulnerability/ PatchThird Party AdvisoryVendor Advisory
- https://azure.microsoft.com/en-us/updates/iot-edge-fix-cve-2019-5736/ PatchThird Party AdvisoryVendor Advisory
- https://blog.dragonsector.pl/2019/02/cve-2019-5736-escape-from-docker-and.html ExploitMitigationThird Party Advisory
- https://brauner.github.io/2019/02/12/privileged-containers.html ExploitTechnical DescriptionThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1664908 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1121967 Issue TrackingPatchThird Party Advisory
- https://cloud.google.com/kubernetes-engine/docs/security-bulletins#february-11-2019-runc Third Party Advisory
- https://github.com/Frichetten/CVE-2019-5736-PoC ExploitThird Party Advisory
- https://github.com/docker/docker-ce/releases/tag/v18.09.2 Release NotesThird Party Advisory
- https://github.com/opencontainers/runc/commit/0a8e4117e7f715d5fbeef398405813ce8e88558b PatchThird Party Advisory
- https://github.com/opencontainers/runc/commit/6635b4f0c6af3810594d2770f662f34ddc15b40d PatchThird Party Advisory
- https://github.com/q3k/cve-2019-5736-poc ExploitThird Party Advisory
- https://github.com/rancher/runc-cve Third Party Advisory
- https://kubernetes.io/blog/2019/02/11/runc-and-cve-2019-5736/ Third Party Advisory
- https://lists.apache.org/thread.html/24e54e3c6b2259e3903b6b8fe26896ac649c481ea99c5739468c92a3%40%3Cdev.dlab.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/a258757af84c5074dc7bf932622020fd4f60cef65a84290380386706%40%3Cuser.mesos.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/a585f64d14c31ab393b90c5f17e41d9765a1a17eec63856ce750af46%40%3Cdev.dlab.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/acacf018c12636e41667e94ac0a1e9244e887eef2debdd474640aa6e%40%3Cdev.dlab.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/b162dd624dc088cd634292f0402282a1d1d0ce853baeae8205bc033c%40%3Cdev.mesos.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rc494623986d76593873ce5a40dd69cb3629400d10750d5d7e96b8587%40%3Cdev.dlab.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E mailing-list
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DLC52IOJN6IQJWJ6CUI6AIUP6GVVG2QP/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EGZKRCKI3Y7FMADO2MENMT4TU24QGHFR/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SWFJGIPYAAAMVSWWI3QWYXGA3ZBU2H4W/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6A4OSFM5GGOWW4ECELV5OHX2XRAUSPH/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-5736
- https://seclists.org/oss-sec/2019/q1/119
- https://security.gentoo.org/glsa/202003-21 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190307-0008/ Third Party Advisory
- https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03410944 Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03913en_us Permissions Required
- https://support.mesosphere.com/s/article/Known-Issue-Container-Runtime-Vulnerability-MSPH-2019-0003 ExploitPatchThird Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190215-runc vendor-advisoryThird Party Advisory
- https://usn.ubuntu.com/4048-1/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-5736
- https://www.exploit-db.com/exploits/46359/ exploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46369/ exploitThird Party AdvisoryVDB Entry
- https://www.openwall.com/lists/oss-security/2019/02/11/2 Mailing ListPatchThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_06 Third Party Advisory
- https://www.twistlock.com/2019/02/11/how-to-mitigate-cve-2019-5736-in-runc-and-docker/ Third Party Advisory
Change history (0)
No recorded changes yet.