Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
go

github.com/opencontainers/runc

View on go registry
36 Total advisories
36 Vulnerabilities
0 Malware

Vulnerabilities

UNKNOWN
Go

CVE-2026-41579

Malicious image with /dev symlink can trigger limited host filesystem integrity violations in github.com/opencontainers/runc

MEDIUM 6.0
Go

CVE-2021-43784

Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC

HIGH 7.6
Go

CVE-2021-30465

mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs

LOW 3.3
Go

CVE-2026-41579

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

UNKNOWN
Go

GHSA-g54h-m393-cpwq

Devices resource list treated as a blacklist by default in github.com/opencontainers/runc

MEDIUM 5.9
Go

CVE-2022-29162

Default inheritable capabilities for linux container should be empty

UNKNOWN
Go

GO-2022-0396

devices resource list treated as a blacklist by default

UNKNOWN
Go

CVE-2023-28642

AppArmor bypass with symlinked /proc in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2023-27561

Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2025-31133

runc container escape via "masked path" abuse due to mount race conditions

HIGH 7.2
Go

GHSA-c5pj-mqfh-rvc3

Withdrawn: Runc allows an arbitrary systemd property to be injected

LOW 2.5
Go

CVE-2023-25809

rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runc

UNKNOWN
Go

CVE-2016-3697

Privilege escalation in github.com/opencontainers/runc

HIGH 7.5
Go

CVE-2019-16884

Incorrect Authorization in runc

HIGH 7.8
Go

CVE-2016-3697

Privilege Elevation in runc

MEDIUM 5.9
Go

CVE-2019-19921

opencontainers runc contains procfs race condition with a shared volume mount

HIGH 8.6
Go

CVE-2024-21626

runc vulnerable to container breakout through process.cwd trickery and leaked fds

UNKNOWN
Go

CVE-2022-29162

Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2016-9962

Information Exposure in RunC in github.com/opencontainers/runc

MEDIUM 6.4
Go

CVE-2016-9962

Information Exposure in RunC

LOW 3.6
Go

CVE-2024-45310

runc can be confused to create empty files/directories on the host

UNKNOWN
Go

CVE-2025-31133

Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2019-19921

Race condition in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2025-52565

Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2023-25809

Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc

HIGH 7.0
Go

CVE-2023-27561

Opencontainers runc Incorrect Authorization vulnerability

UNKNOWN
Go

CVE-2025-52881

Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2025-52881

runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects

MEDIUM 6.1
Go

CVE-2023-28642

runc AppArmor bypass with symlinked /proc

UNKNOWN
Go

CVE-2019-16884

Authorization bypass in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2024-21626

Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2021-43784

Namespace restriction bypass in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2024-45310

Can be confused to create empty files/directories on the host in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2021-30465

Mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs in github.com/opencontainers/runc

UNKNOWN
Go

CVE-2025-52565

runc container escape with malicious config due to /dev/console mount and related races

UNKNOWN
Go

CVE-2025-27612

WITHDRAWN: Libcontainer is affected by capabilities elevation in github.com/opencontainers/runc

Ready to move

Start Securing

Free, no credit card | First findings in minutes