CVE-2024-21626
High · CVSS 8.6runc — File descriptor leak leading to container escape / host filesystem namespace access
- CVSS
- 8.6
- nvd
- EPSS
- 18.1%
- 97th pct
- KEV
- No
- Class
- oss containerizable
- CWE-403, CWE-668, CWE-668, CWE-200
Description
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.
Search profile — drives PoC discovery
Ranked PoCs (62) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 6
- ★ 5
- ★ 4
- ★ 3
- ★ 1
- ★ 0
- ★ 2
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 77
- ★ 2
- ★ 2
- ★ 1FlojBoj/CVE-2024-21626 needs reviewgh_search
- ★ 1
- ★ 1
- ★ 08-cm/kube-dump needs reviewtrickest
- ★ 0AMH-glitch/CHWA-LB-IDSDATASET needs reviewtrickest
- ★ 0DrAmmarMoustafa/CHASE-LB-Container-Dataset needs reviewtrickest
- ★ 0DrAmmarMoustafa/CHASE-LB-Container-IDS-Dataset needs reviewtrickest
- ★ 0EGI-Federation/SVG-advisories needs reviewtrickest
- ★ 0FishAnonymous/CAShift-Record needs reviewtrickest
- ★ 0GhostTroops/TOP needs reviewtrickest
- ★ 0Metarget/metarget needs reviewtrickest
- ★ 0Noah4Puppy/CVE-2024-21262 needs reviewtrickest
- ★ 0PuddinCat/GithubRepoSpider needs reviewtrickest
- ★ 0R3DRUN3/R3DRUN3 needs reviewtrickest
- ★ 0R4mbb/CVE-2024-21626 needs reviewtrickest
- ★ 0
- ★ 0Sk3pper/CVE-2024-21626-old-docker-versions needs reviewgh_search · Shell
- ★ 0SrcVme50/Runner needs reviewtrickest
- ★ 0Wall1e/CVE-2024-21626-POC needs reviewtrickest
- ★ 0adaammmeeee/little-joke needs reviewgh_search · Shell
- ★ 0alban/runc-vuln-detector needs reviewtrickest
- ★ 0alban/runc-vuln-gadget needs reviewtrickest
- ★ 0aneasystone/github-trending needs reviewtrickest
- ★ 0anik-chy/Final-project-6130 needs reviewtrickest
- ★ 0bfengj/Cloud-Security needs reviewtrickest
- ★ 0trickest
- ★ 0chrisregy23/Container-Security needs reviewtrickest
- ★ 0fireinrain/github-trending needs reviewtrickest
- ★ 0fkie-cad/nvd-json-data-feeds needs reviewtrickest
- ★ 0jafshare/GithubTrending needs reviewtrickest
- ★ 0jiayy/android_vuln_poc-exp needs reviewtrickest
- ★ 0k8sstormcenter/honeycluster needs reviewtrickest
- ★ 0laysakura/resume-jp needs reviewtrickest
- ★ 0mmedhat1910/masters-testing-apps needs reviewtrickest
- ★ 0nclsbayona/leaky-vessels needs reviewtrickest
- ★ 0opencontainers-sec/go-containersec needs reviewtrickest
- ★ 0rpinuaga/atomic-container needs reviewtrickest
- ★ 0ssst0n3/c-listener needs reviewtrickest
- ★ 0ssst0n3/fd-listener needs reviewtrickest
- ★ 0tarihub/offlinepost needs reviewtrickest
- ★ 0zhanpengliu-tencent/medium-cve needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| Go | github.com/opencontainers/runc | 1.0.0-rc93 → 1.1.12 |
References
- http://packetstormsecurity.com/files/176993/runc-1.1.11-File-Descriptor-Leak-Privilege-Escalation.html
- http://www.openwall.com/lists/oss-security/2024/02/01/1
- http://www.openwall.com/lists/oss-security/2024/02/02/3
- https://github.com/opencontainers/runc/commit/02120488a4c0fc487d1ed2867e901eeed7ce8ecf
- https://github.com/opencontainers/runc/releases/tag/v1.1.12
- https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv
- https://lists.debian.org/debian-lts-announce/2024/02/msg00005.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2NLXNE23Q5ESQUAI22Z7A63JX2WMPJ2J/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SYMO3BANINS6RGFQFKPRG4FIOJ7GWYTL/
- http://packetstormsecurity.com/files/176993/runc-1.1.11-File-Descriptor-Leak-Privilege-Escalation.html
- http://www.openwall.com/lists/oss-security/2024/02/01/1
- http://www.openwall.com/lists/oss-security/2024/02/02/3
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:10:12.581Z