Back

MEDIUM

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

Published Jul 1, 2026

Description

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string which allow an image with /dev as a symlink to trick runc into deleting files called ptmx on the host or creating a hardcoded set of symlinks with specific names and targets in an arbitrary pre-existing host directory. This issue is not exploitable under Docker, because Docker creates a top-level read-only layer that masks any malicious /dev symlink present in the container image — unlike some other Linux container tooling, whose higher-level runtimes built on runc remain exposed to exploitation via a malicious image. This issue has been fixed in versions 1.3.6, 1.4.3 and 1.5.0.

Affected products

Remediation

Red Hat statement

On Red Hat Enterprise Linux and Red Hat CoreOS, this issue is reachable through higher-level runtimes that use runc without Docker’s read-only layer masking (for example Podman on RHEL and CRI-O on RHCOS). Red Hat scores this as a Low impact integrity issue: a malicious image that is run can cause only limited host filesystem changes (deletion of files named ptmx, or creation of a fixed set of symlinks). SELinux in enforcing mode and user-namespace/rootless configurations may further reduce practical impact but are not treated as a complete fix.

Red Hat mitigation

Run only trusted images.Prefer rootless or user-namespace configurations where practical, and keep SELinux in enforcing mode so host filesystem impact is further limited. These steps reduce exposure but do not fully eliminate the flaw; upgrade to a fixed runc release as soon as it is available.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 1, 2026
Updated Jul 1, 2026
Reserved Apr 21, 2026
CISA Vulnrichment
Updated Jul 1, 2026
NVD
Status Analyzed
Modified Jul 2, 2026
Red Hat
Severity Low
Public date Jul 1, 2026
GHSA-XJVP-4FHW-GC47