Opencontainers / Runc
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41579 | runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations | MEDIUM | 4.8 | Jul 1, 2026 |
| CVE-2025-52881 | runc: LSM labels can be bypassed with malicious config using dummy procfs files | HIGH | 7.3 | Nov 6, 2025 |
| CVE-2025-52565 | container escape due to /dev/console mount and related races | HIGH | 8.4 | Nov 6, 2025 |
| CVE-2025-31133 | runc container escape via "masked path" abuse due to mount race conditions | HIGH | 7.3 | Nov 6, 2025 |
| CVE-2024-45310 | runc can be confused to create empty files/directories on the host | MEDIUM | 4.8 | Sep 3, 2024 |
| CVE-2024-21626 | runc container breakout through process.cwd trickery and leaked fds | HIGH | 8.6 | Jan 31, 2024 |
| CVE-2023-25809 | rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runc | MEDIUM | 6.3 | Mar 29, 2023 |
| CVE-2023-28642 | AppArmor bypass with symlinked /proc in runc | HIGH | 7.8 | Mar 29, 2023 |
| CVE-2022-29162 | Incorrect Default Permissions in runc | HIGH | 7.8 | May 17, 2022 |
| CVE-2021-43784 | Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration | MEDIUM | 6.0 | Dec 6, 2021 |
Showing 1 to 10 of 10 CVEs