Linux / Runc
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41579 | runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations | MEDIUM | 4.8 | Jul 1, 2026 |
| CVE-2025-52881 | runc: LSM labels can be bypassed with malicious config using dummy procfs files | HIGH | 7.3 | Nov 6, 2025 |
| CVE-2025-52565 | container escape due to /dev/console mount and related races | HIGH | 8.4 | Nov 6, 2025 |
| CVE-2025-31133 | runc container escape via "masked path" abuse due to mount race conditions | HIGH | 7.3 | Nov 6, 2025 |
| CVE-2024-45310 | runc can be confused to create empty files/directories on the host | MEDIUM | 4.8 | Sep 3, 2024 |
| CVE-2024-21626 | runc container breakout through process.cwd trickery and leaked fds | HIGH | 8.6 | Jan 31, 2024 |
| CVE-2023-25809 | rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runc | MEDIUM | 6.3 | Mar 29, 2023 |
| CVE-2023-28642 | AppArmor bypass with symlinked /proc in runc | HIGH | 7.8 | Mar 29, 2023 |
| CVE-2023-27561 | runc: volume mount race condition (regression of CVE-2019-19921) | HIGH | 7.0 | Mar 3, 2023 |
| CVE-2022-29162 | Incorrect Default Permissions in runc | HIGH | 7.8 | May 17, 2022 |
| CVE-2022-24769 | Default inheritable capabilities for linux container should be empty | MEDIUM | 5.9 | Mar 24, 2022 |
| CVE-2021-43784 | Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration | MEDIUM | 6.0 | Dec 6, 2021 |
| CVE-2021-30465 | runc: vulnerable to symlink exchange attack | HIGH | 8.5 | May 27, 2021 |
| CVE-2019-19921 | runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation | HIGH | 7.0 | Feb 12, 2020 |
| CVE-2019-16884 | runc: AppArmor/SELinux bypass with malicious image that specifies a volume at /proc | HIGH | 7.5 | Sep 25, 2019 |
| CVE-2019-5736 | runc: Execution of malicious containers allows for container escape and access to host filesystem | HIGH | 8.6 | Feb 11, 2019 |
| CVE-2016-3697 | docker: privilege escalation via confusion of usernames and UIDs | HIGH | 7.8 | Jun 1, 2016 |
Showing 1 to 17 of 17 CVEs