Severity
7.0HIGH
EPSS
0.1%
top 68.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateNov 5

Description

runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages6 packages

Gogithub.com/opencontainers/runc< 1.0.0-rc9.0.20200122160610-2fc03cc11c77
CVEListV5opencontainers/runc1.2.7, < 1.2.8
Debianrunc< 1.0.0~rc10+dfsg1-1+3
Ubunturunc< 1.0.0~rc10-0ubuntu1~18.04.2+1

Also affects: Debian Linux 10.0, 9.0, Ubuntu Linux 18.04, 19.10, Openshift Container Platform 4.1, 4.2

Patches

🔴Vulnerability Details

11
GHSA
runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects2025-11-05
Kernel
Merge tag 'vfs-6.17-rc1.nsfs' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs2025-07-28
Kernel
uapi: export PROCFS_ROOT_INO2025-07-08
OSV
runc vulnerabilities2023-05-23
GHSA
Opencontainers runc Incorrect Authorization vulnerability2023-03-03

📋Vendor Advisories

6
Ubuntu
runC vulnerabilities2023-05-23
Microsoft
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges related to libcontainer/rootfs_linux.go. To exploit this an attacker must be able to spawn two containers with custo2023-03-14
Red Hat
runc: volume mount race condition (regression of CVE-2019-19921)2023-02-20
Ubuntu
runC vulnerabilities2020-03-09
Red Hat
runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation2019-12-21

💬Community

4
Bugzilla
CVE-2019-19921 docker: runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation [openstack-rdo]2020-01-29
Bugzilla
CVE-2019-19921 runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation2020-01-29
Bugzilla
CVE-2019-19921 runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation [fedora-all]2020-01-29
Bugzilla
CVE-2019-19921 docker: runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation [fedora-all]2020-01-29
CVE-2019-19921 (HIGH CVSS 7) | runc through 1.0.0-rc9 has Incorrec | cvebase.io