Runc · Runc · CVE-2026-41579
**Name of the Vulnerable Software and Affected Versions**
runc versions prior to 1.3.6
runc versions prior to 1.4.3
runc versions prior to 1.5.0-rc.3
**Description**
A flaw involving a `/dev` symlink allows a malicious container image to obtain limited write access to the host filesystem. This issue occurs during the rootfs setup process.
**Recommendations**
Update to version 1.3.6.
Update to version 1.4.3.
Update to version 1.5.0-rc.3.