Home/Product/linuxfoundation runc
Product

linuxfoundation runc

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-52881
< 1.2.8
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2
7.5HIGH
CVE-2025-52565
>= 1.0.1 and < 1.2.8
runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0
7.5HIGH
CVE-2025-31133
< 1.2.8
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1
7.8HIGH
CVE-2024-45310
< 1.1.14
runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2
3.6LOW
CVE-2024-21626
< 1.1.12
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, du
8.6HIGH
CVE-2023-28642
< 1.1.5
runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypas
6.1MEDIUM
CVE-2023-25809
< 1.1.5
runc is a CLI tool for spawning and running containers according to the OCI specification. In affected versions it was found that
5.0MEDIUM
CVE-2023-27561
< 1.1.5
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To e
7.0HIGH
CVE-2022-29162
< 1.1.2
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior
5.9MEDIUM
CVE-2022-24769
< 1.1.2
Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Dock
5.9MEDIUM
CVE-2021-43784
< 1.0.3
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used inter
6.0MEDIUM
CVE-2021-30465
<= 0.1.1
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker m
8.5HIGH
CVE-2019-19921
<= 0.1.1
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go.
7.0HIGH
CVE-2019-16884
>= 0.0.1 and <= 0.1.1
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcon
7.5HIGH
CVE-2019-5736
<= 0.1.1
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and
8.6HIGH
CVE-2016-3697
<= 0.0.9
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential us
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin