runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
Published Jul 1, 2026
4.8
MEDIUMCVSS 4.0
EPSS 0.19%
Description
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string which allow an image with /dev as a symlink to trick runc into deleting files called ptmx on the host or creating a hardcoded set of symlinks with specific names and targets in an arbitrary pre-existing host directory. This issue is not exploitable under Docker, because Docker creates a top-level read-only layer that masks any malicious /dev symlink present in the container image — unlike some other Linux container tooling, whose higher-level runtimes built on runc remain exposed to exploitation via a malicious image. This issue has been fixed in versions 1.3.6, 1.4.3 and 1.5.0.
Affected products
-
- Version < 1.3.6StatusaffectedConstraints-
- Version >= 1.4.0-rc.1, < 1.4.3StatusaffectedConstraints-
- Version >= 1.5.0-rc.1, < 1.5.0-rc.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Opencontainers | Runc | n/a |
|
- < 1.3.6
- ≥ 1.4.0 · < 1.4.3
- 1.5.0
- 1.5.0
No data.
Red Hat Enterprise Linux 8
container-tools:rhel8/runc
Fix deferred
Red Hat Enterprise Linux 9
runc
Fix deferred
Red Hat Hardened Images
buildah
Not affected
Red Hat Hardened Images
podman
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Under investigation
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
Red Hat OpenShift Container Platform 4
runc
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | container-tools:rhel8/runc | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | runc | Fix deferred | n/a |
| Red Hat Hardened Images | buildah | Not affected | n/a |
| Red Hat Hardened Images | podman | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Under investigation | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | runc | Fix deferred | n/a |
github.com/opencontainers/runc
Go
Introduced 0 Fixed 1.3.6github.com/opencontainers/runc
Go
Introduced 1.4.0 Fixed 1.4.3github.com/opencontainers/runc
Go
Introduced 1.5.0-rc.1 Fixed 1.5.0-rc.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/opencontainers/runc | 0 | 1.3.6 |
| Go | github.com/opencontainers/runc | 1.4.0 | 1.4.3 |
| Go | github.com/opencontainers/runc | 1.5.0-rc.1 | 1.5.0-rc.3 |
Remediation
Red Hat statement
On Red Hat Enterprise Linux and Red Hat CoreOS, this issue is reachable through higher-level runtimes that use runc without Docker’s read-only layer masking (for example Podman on RHEL and CRI-O on RHCOS). Red Hat scores this as a Low impact integrity issue: a malicious image that is run can cause only limited host filesystem changes (deletion of files named ptmx, or creation of a fixed set of symlinks). SELinux in enforcing mode and user-namespace/rootless configurations may further reduce practical impact but are not treated as a complete fix.
Red Hat mitigation
Run only trusted images.Prefer rootless or user-namespace configurations where practical, and keep SELinux in enforcing mode so host filesystem impact is further limited. These steps reduce exposure but do not fully eliminate the flaw; upgrade to a fixed runc release as soon as it is available.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-41579 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2495813 Issue Tracking
- https://github.com/advisories/GHSA-xjvp-4fhw-gc47 Advisory
- https://github.com/opencontainers/runc/commit/864db8042dbb x_refsource_MISCPatch
- https://github.com/opencontainers/runc/security/advisories/GHSA-xjvp-4fhw-gc47 x_refsource_CONFIRMMitigationPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41579
- https://www.cve.org/CVERecord?id=CVE-2026-41579
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-41579 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2495813 | Issue Tracking | |
| https://github.com/advisories/GHSA-xjvp-4fhw-gc47 | Advisory | |
| https://github.com/opencontainers/runc/commit/864db8042dbb | x_refsource_MISCPatch | |
| https://github.com/opencontainers/runc/security/advisories/GHSA-xjvp-4fhw-gc47 | x_refsource_CONFIRMMitigationPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41579 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-41579 |
Change history (0)
No recorded changes yet.