github.com/opencontainers/runc
CLI tool for spawning and running containers according to the OCI specification
Activity
- Latest release
- 2mo ago
- Total releases
- 63
- Cadence
- ~28 days
- Last 12 months
- 17
Reach
- Stars
- 13.4k
Details
- First release
- Jul 17, 2015
| Version | Released | |
|---|---|---|
v1.5.1
patch
|
v1.5.1
patch
Dependencies (23)
+ 15 more |
|
v1.5.0
minor
|
v1.5.0
minor
Dependencies (23)
+ 15 more |
|
v1.4.3
patch
|
v1.4.3
patch
Dependencies (22)
+ 14 more |
|
v1.3.6
patch
|
v1.3.6
patch
Dependencies (21)
+ 13 more |
|
v1.5.0-rc.3
pre
|
v1.5.0-rc.3
pre
Dependencies (23)
+ 15 more |
|
v1.5.0-rc.2
pre
1 CVE
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev |
v1.5.0-rc.2
pre
Dependencies (23)
+ 15 more |
|
v1.4.2
patch
1 CVE
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev |
v1.4.2
patch
Dependencies (22)
+ 14 more |
|
v1.3.5
patch
1 CVE
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev |
v1.3.5
patch
Dependencies (21)
+ 13 more |
|
v1.5.0-rc.1
pre
1 CVE
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev |
v1.5.0-rc.1
pre
Dependencies (22)
+ 14 more |
|
v1.4.1
patch
1 CVE
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (22)
+ 14 more |
|
v1.2.9
patch
1 CVE
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev |
v1.2.9
patch
Dependencies (21)
+ 13 more |
|
v1.3.4
patch
1 CVE
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev |
v1.3.4
patch
Dependencies (21)
+ 13 more |
|
v1.4.0
minor
1 CVE
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (22)
+ 14 more |
|
v1.4.0-rc.3
pre
|
v1.4.0-rc.3
pre
Dependencies (22)
+ 14 more |
|
v1.3.3
patch
1 CVE
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev |
v1.3.3
patch
Dependencies (21)
+ 13 more |
|
v1.4.0-rc.2
pre
3 CVEs
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.0-rc.2
pre
Dependencies (22)
+ 14 more |
|
v1.3.2
minor
4 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.2
minor
Dependencies (21)
+ 13 more |
|
v1.4.0-rc.1
pre
3 CVEs
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.0-rc.1
pre
Dependencies (22)
+ 14 more |
|
v1.3.1
patch
4 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.1
patch
Dependencies (21)
+ 13 more |
|
v1.3.0
minor
4 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.0
minor
Dependencies (21)
+ 13 more |
|
v1.3.0-rc.2
pre
4 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.0-rc.2
pre
Dependencies (21)
+ 13 more |
|
v1.3.0-rc.1
pre
4 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.0-rc.1
pre
Dependencies (21)
+ 13 more |
|
v1.2.4
patch
4 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.4
patch
Dependencies (21)
+ 13 more |
|
v1.2.2
patch
4 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (21)
+ 13 more |
|
v1.2.1
patch
4 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (21)
+ 13 more |
|
v1.2.0
minor
4 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (21)
+ 13 more |
|
v1.1.15
patch
4 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.15
patch
Dependencies (19)
+ 11 more |
|
v1.2.0-rc.3
pre
4 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.0-rc.3
pre
Dependencies (20)
+ 12 more |
|
v1.1.14
patch
4 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.14
patch
Dependencies (19)
+ 11 more |
|
v1.2.0-rc.2
pre
5 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.0-rc.2
pre
Dependencies (20)
+ 12 more |
|
v1.1.13
patch
5 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.13
patch
Dependencies (19)
+ 11 more |
|
v1.2.0-rc.1
pre
5 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.0-rc.1
pre
Dependencies (20)
+ 12 more |
|
v1.1.12
patch
5 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.12
patch
Dependencies (19)
+ 11 more |
|
v1.1.11
patch
6 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.11
patch
Dependencies (19)
+ 11 more |
|
v1.1.10
patch
6 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.10
patch
Dependencies (19)
+ 11 more |
|
v1.1.9
patch
6 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.9
patch
Dependencies (19)
+ 11 more |
|
v1.1.8
patch
6 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.8
patch
Dependencies (19)
+ 11 more |
|
v1.1.7
patch
6 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.7
patch
Dependencies (19)
+ 11 more |
|
v1.1.5
patch
6 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.5
patch
Dependencies (19)
+ 11 more |
|
v1.1.4
patch
9 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-28642
GO-2023-1683
GHSA-g2j6-57v7-gm8c
Aug 20, 2024
AppArmor bypass with symlinked /proc in github.com/opencontainers/runc AppArmor bypass with symlinked /proc in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25809
GO-2023-1682
GHSA-m8cg-xc2p-r3fc
Aug 20, 2024
Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-27561
GO-2023-1627
GHSA-vpvm-3wq2-2wvm
Aug 20, 2024
Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc Fixed in
1.1.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.4
patch
Dependencies (19)
+ 11 more |
|
v1.1.3
patch
9 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-28642
GO-2023-1683
GHSA-g2j6-57v7-gm8c
Aug 20, 2024
AppArmor bypass with symlinked /proc in github.com/opencontainers/runc AppArmor bypass with symlinked /proc in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25809
GO-2023-1682
GHSA-m8cg-xc2p-r3fc
Aug 20, 2024
Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-27561
GO-2023-1627
GHSA-vpvm-3wq2-2wvm
Aug 20, 2024
Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc Fixed in
1.1.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.3
patch
Dependencies (19)
+ 11 more |
|
v1.1.2
patch
9 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-28642
GO-2023-1683
GHSA-g2j6-57v7-gm8c
Aug 20, 2024
AppArmor bypass with symlinked /proc in github.com/opencontainers/runc AppArmor bypass with symlinked /proc in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25809
GO-2023-1682
GHSA-m8cg-xc2p-r3fc
Aug 20, 2024
Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-27561
GO-2023-1627
GHSA-vpvm-3wq2-2wvm
Aug 20, 2024
Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc Fixed in
1.1.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.2
patch
Dependencies (19)
+ 11 more |
|
v1.1.0
minor
10 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29162
GO-2022-0452
GHSA-f3fp-gc8g-vw66
Aug 21, 2024
Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Fixed in
1.1.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-28642
GO-2023-1683
GHSA-g2j6-57v7-gm8c
Aug 20, 2024
AppArmor bypass with symlinked /proc in github.com/opencontainers/runc AppArmor bypass with symlinked /proc in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25809
GO-2023-1682
GHSA-m8cg-xc2p-r3fc
Aug 20, 2024
Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-27561
GO-2023-1627
GHSA-vpvm-3wq2-2wvm
Aug 20, 2024
Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc Fixed in
1.1.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (19)
+ 11 more |
|
v1.0.3
patch
11 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29162
GO-2022-0452
GHSA-f3fp-gc8g-vw66
Aug 21, 2024
Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Fixed in
1.1.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-28642
GO-2023-1683
GHSA-g2j6-57v7-gm8c
Aug 20, 2024
AppArmor bypass with symlinked /proc in github.com/opencontainers/runc AppArmor bypass with symlinked /proc in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25809
GO-2023-1682
GHSA-m8cg-xc2p-r3fc
Aug 20, 2024
Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-27561
GO-2023-1627
GHSA-vpvm-3wq2-2wvm
Aug 20, 2024
Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc Fixed in
1.1.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-43784
GO-2022-0274
GHSA-v95c-p5hm-xq8f
Jul 15, 2022
Namespace restriction bypass in github.com/opencontainers/runc An attacker with partial control over the bind mount sources of a new container can bypass namespace restrictions. Fixed in
1.1.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.3
patch
Dependencies (21)
+ 13 more |
|
v1.0.1
major
11 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29162
GO-2022-0452
GHSA-f3fp-gc8g-vw66
Aug 21, 2024
Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Fixed in
1.1.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-28642
GO-2023-1683
GHSA-g2j6-57v7-gm8c
Aug 20, 2024
AppArmor bypass with symlinked /proc in github.com/opencontainers/runc AppArmor bypass with symlinked /proc in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25809
GO-2023-1682
GHSA-m8cg-xc2p-r3fc
Aug 20, 2024
Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-27561
GO-2023-1627
GHSA-vpvm-3wq2-2wvm
Aug 20, 2024
Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc Fixed in
1.1.5
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-43784
GO-2022-0274
GHSA-v95c-p5hm-xq8f
Jul 15, 2022
Namespace restriction bypass in github.com/opencontainers/runc An attacker with partial control over the bind mount sources of a new container can bypass namespace restrictions. Fixed in
1.1.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.1
major
Dependencies (21)
+ 13 more |
|
v1.0.0-rc94
pre
10 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-30465
GO-2022-0914
GHSA-c3xm-pvg7-gh7r
Aug 21, 2024
Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc Fixed in
1.0.0-rc95
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29162
GO-2022-0452
GHSA-f3fp-gc8g-vw66
Aug 21, 2024
Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Fixed in
1.1.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-28642
GO-2023-1683
GHSA-g2j6-57v7-gm8c
Aug 20, 2024
AppArmor bypass with symlinked /proc in github.com/opencontainers/runc AppArmor bypass with symlinked /proc in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25809
GO-2023-1682
GHSA-m8cg-xc2p-r3fc
Aug 20, 2024
Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-21626
GO-2024-2491
GHSA-xr7r-f8xq-vfvv
Jun 28, 2024
Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc Fixed in
1.1.12
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0-rc94
pre
Dependencies (21)
+ 13 more |
|
v1.0.0-rc92
pre
9 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-30465
GO-2022-0914
GHSA-c3xm-pvg7-gh7r
Aug 21, 2024
Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc Fixed in
1.0.0-rc95
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29162
GO-2022-0452
GHSA-f3fp-gc8g-vw66
Aug 21, 2024
Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Fixed in
1.1.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-28642
GO-2023-1683
GHSA-g2j6-57v7-gm8c
Aug 20, 2024
AppArmor bypass with symlinked /proc in github.com/opencontainers/runc AppArmor bypass with symlinked /proc in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25809
GO-2023-1682
GHSA-m8cg-xc2p-r3fc
Aug 20, 2024
Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0-rc92
pre
Dependencies (19)
+ 11 more |
|
v1.0.0-rc91
pre
9 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-30465
GO-2022-0914
GHSA-c3xm-pvg7-gh7r
Aug 21, 2024
Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc Fixed in
1.0.0-rc95
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29162
GO-2022-0452
GHSA-f3fp-gc8g-vw66
Aug 21, 2024
Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Fixed in
1.1.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-28642
GO-2023-1683
GHSA-g2j6-57v7-gm8c
Aug 20, 2024
AppArmor bypass with symlinked /proc in github.com/opencontainers/runc AppArmor bypass with symlinked /proc in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25809
GO-2023-1682
GHSA-m8cg-xc2p-r3fc
Aug 20, 2024
Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0-rc91
pre
Dependencies (19)
+ 11 more |
|
v1.0.0-rc10
pre
12 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-30465
GO-2022-0914
GHSA-c3xm-pvg7-gh7r
Aug 21, 2024
Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc Fixed in
1.0.0-rc95
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2016-9962
GO-2022-0835
GHSA-gp4j-w3vj-7299
Aug 21, 2024
Information Exposure in RunC in github.com/opencontainers/runc Information Exposure in RunC in github.com/opencontainers/runc Fixed in
1.0.0-rc3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29162
GO-2022-0452
GHSA-f3fp-gc8g-vw66
Aug 21, 2024
Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Fixed in
1.1.2
References
Updated Feb 04, 2026 · Source: OSV.dev
GO-2022-0396
GHSA-g54h-m393-cpwq
Aug 21, 2024
Devices resource list treated as a blacklist by default in github.com/opencontainers/runc Devices resource list treated as a blacklist by default in github.com/opencontainers/runc Fixed in
1.0.0-rc91
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-28642
GO-2023-1683
GHSA-g2j6-57v7-gm8c
Aug 20, 2024
AppArmor bypass with symlinked /proc in github.com/opencontainers/runc AppArmor bypass with symlinked /proc in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25809
GO-2023-1682
GHSA-m8cg-xc2p-r3fc
Aug 20, 2024
Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2019-16884
GHSA-fgv8-vj5c-2ppq
GO-2021-0085
Feb 22, 2022
Incorrect Authorization in runc
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory. Fixed in
1.0.0-rc8.0.20190930145003-cad42f6e0932
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-19921
GHSA-fh74-hm69-rqjw
GO-2021-0087
May 27, 2021
opencontainers runc contains procfs race condition with a shared volume mount
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactBy crafting a malicious root filesystem (with In order to exploit this bug, an untrusted user must be able to spawn custom containers with custom mount configurations (such that a volume is shared between two containers). It should be noted that we consider this to be a fairly high level of access for an untrusted user -- and we do not recommend allowing completely untrusted users to have such degrees of access without further restrictions. Specific Go Package Affectedgithub.com/opencontainers/runc/libcontainer PatchesThis vulnerability has been fixed in WorkaroundsIf you are not providing the ability for untrusted users to configure mountpoints for Additionally, it appears as though it is not possible to exploit this vulnerability through Docker (due to the order of mounts Docker generates). However you should not depend on this, as it may be possible to work around this roadblock. CreditsThis vulnerability was discovered by Cure53, as part of a third-party security audit. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.0.0-rc9.0.20200122160610-2fc03cc11c77
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.0.0-rc10
pre
|
|
v1.0.0-rc9
pre
11 CVEs
CVE-2026-41579
GO-2026-5761
GHSA-xjvp-4fhw-gc47
Jul 07, 2026
Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc Fixed in
1.3.6
1.4.3
1.5.0-rc.3
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2025-31133
GO-2025-4096
GHSA-9493-h29p-rfm2
Nov 18, 2025
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52565
GO-2025-4097
GHSA-qw9x-cqr3-wc7r
Nov 18, 2025
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-52881
GO-2025-4098
GHSA-cgrx-mc8f-2prm
Nov 18, 2025
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc Fixed in
1.2.8
1.3.3
1.4.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-45310
GO-2024-3110
GHSA-jfvp-7x6p-h2pv
Sep 06, 2024
Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Can be confused to create empty files/directories on the host in github.com/opencontainers/runc Fixed in
1.1.14
1.2.0-rc.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-30465
GO-2022-0914
GHSA-c3xm-pvg7-gh7r
Aug 21, 2024
Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc Fixed in
1.0.0-rc95
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-29162
GO-2022-0452
GHSA-f3fp-gc8g-vw66
Aug 21, 2024
Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc Fixed in
1.1.2
References
Updated Feb 04, 2026 · Source: OSV.dev
GO-2022-0396
GHSA-g54h-m393-cpwq
Aug 21, 2024
Devices resource list treated as a blacklist by default in github.com/opencontainers/runc Devices resource list treated as a blacklist by default in github.com/opencontainers/runc Fixed in
1.0.0-rc91
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-28642
GO-2023-1683
GHSA-g2j6-57v7-gm8c
Aug 20, 2024
AppArmor bypass with symlinked /proc in github.com/opencontainers/runc AppArmor bypass with symlinked /proc in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25809
GO-2023-1682
GHSA-m8cg-xc2p-r3fc
Aug 20, 2024
Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc Fixed in
1.1.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2019-19921
GHSA-fh74-hm69-rqjw
GO-2021-0087
May 27, 2021
opencontainers runc contains procfs race condition with a shared volume mount
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactBy crafting a malicious root filesystem (with In order to exploit this bug, an untrusted user must be able to spawn custom containers with custom mount configurations (such that a volume is shared between two containers). It should be noted that we consider this to be a fairly high level of access for an untrusted user -- and we do not recommend allowing completely untrusted users to have such degrees of access without further restrictions. Specific Go Package Affectedgithub.com/opencontainers/runc/libcontainer PatchesThis vulnerability has been fixed in WorkaroundsIf you are not providing the ability for untrusted users to configure mountpoints for Additionally, it appears as though it is not possible to exploit this vulnerability through Docker (due to the order of mounts Docker generates). However you should not depend on this, as it may be possible to work around this roadblock. CreditsThis vulnerability was discovered by Cure53, as part of a third-party security audit. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.0.0-rc9.0.20200122160610-2fc03cc11c77
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.0.0-rc9
pre
|