runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

Project Subscriptions

Vendors Products
Fedoraproject Subscribe
Linuxfoundation Subscribe
Enterprise Linux Subscribe
Ocp Tools Subscribe
Openshift Subscribe
Rhel Aus Subscribe
Rhel E4s Subscribe
Rhel Eus Subscribe
Rhel Extras Other Subscribe
Rhel Tus Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3735-1 runc security update
Debian DSA Debian DSA DSA-5615-1 runc security update
EUVD EUVD EUVD-2024-0459 runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.
Github GHSA Github GHSA GHSA-xr7r-f8xq-vfvv runc vulnerable to container breakout through process.cwd trickery and leaked fds
Ubuntu USN Ubuntu USN USN-6619-1 runC vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://packetstormsecurity.com/files/176993/runc-1.1.11-File-Descriptor-Leak-Privilege-Escalation.html cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2024/02/01/1 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2024/02/02/3 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0645 cve-icon
https://access.redhat.com/errata/RHSA-2024:0662 cve-icon
https://access.redhat.com/errata/RHSA-2024:0666 cve-icon
https://access.redhat.com/errata/RHSA-2024:0670 cve-icon
https://access.redhat.com/errata/RHSA-2024:0684 cve-icon
https://access.redhat.com/errata/RHSA-2024:0717 cve-icon
https://access.redhat.com/errata/RHSA-2024:0748 cve-icon
https://access.redhat.com/errata/RHSA-2024:0752 cve-icon
https://access.redhat.com/errata/RHSA-2024:0755 cve-icon
https://access.redhat.com/errata/RHSA-2024:0756 cve-icon
https://access.redhat.com/errata/RHSA-2024:0757 cve-icon
https://access.redhat.com/errata/RHSA-2024:0758 cve-icon
https://access.redhat.com/errata/RHSA-2024:0759 cve-icon
https://access.redhat.com/errata/RHSA-2024:0760 cve-icon
https://access.redhat.com/errata/RHSA-2024:0764 cve-icon
https://access.redhat.com/errata/RHSA-2024:10149 cve-icon
https://access.redhat.com/errata/RHSA-2024:10520 cve-icon
https://access.redhat.com/errata/RHSA-2024:10525 cve-icon
https://access.redhat.com/errata/RHSA-2024:10841 cve-icon
https://access.redhat.com/errata/RHSA-2024:1270 cve-icon
https://access.redhat.com/errata/RHSA-2024:4597 cve-icon
https://access.redhat.com/errata/RHSA-2025:0115 cve-icon
https://access.redhat.com/errata/RHSA-2025:0650 cve-icon
https://access.redhat.com/errata/RHSA-2025:1711 cve-icon
https://access.redhat.com/errata/RHSA-2025:2441 cve-icon
https://access.redhat.com/errata/RHSA-2025:2701 cve-icon
https://access.redhat.com/errata/RHSA-2025:2710 cve-icon
https://access.redhat.com/security/cve/CVE-2024-21626 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2258725 cve-icon
https://github.com/opencontainers/runc/commit/02120488a4c0fc487d1ed2867e901eeed7ce8ecf cve-icon cve-icon
https://github.com/opencontainers/runc/releases/tag/v1.1.12 cve-icon cve-icon
https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv cve-icon cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2024/02/msg00005.html cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/[email protected]/message/2NLXNE23Q5ESQUAI22Z7A63JX2WMPJ2J/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/[email protected]/message/SYMO3BANINS6RGFQFKPRG4FIOJ7GWYTL/ cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2024-21626 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-21626.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2024-21626 cve-icon
https://www.vicarius.io/vsociety/posts/leaky-vessels-part-1-cve-2024-21626 cve-icon
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.03057}

epss

{'score': 0.03846}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0331}

epss

{'score': 0.03057}


Thu, 15 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Feb 2025 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.15::el8

Thu, 13 Feb 2025 17:45:00 +0000

Type Values Removed Values Added
Description runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue. runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

Thu, 12 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.15::el9

Thu, 05 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.14::el9

Wed, 04 Dec 2024 02:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.17::el9

Wed, 27 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.16::el9

Fri, 22 Nov 2024 12:00:00 +0000


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-13T12:04:35.841Z

Reserved: 2023-12-29T03:00:44.953Z

Link: CVE-2024-21626

cve-icon Vulnrichment

Updated: 2024-08-19T07:48:05.378Z

cve-icon NVD

Status : Modified

Published: 2024-01-31T22:15:53.780

Modified: 2026-07-20T12:16:55.640

Link: CVE-2024-21626

cve-icon Redhat

Severity : Important

Publid Date: 2024-01-31T20:01:00Z

Links: CVE-2024-21626 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses