PT-2026-49168 · Runc · Runc

·

CVE-2026-41579

·

Published

2026-06-13

·

Updated

2026-08-10

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions runc versions prior to 1.3.6 runc versions prior to 1.4.3 runc versions prior to 1.5.0-rc.3
Description A flaw involving a /dev symlink allows a malicious container image to obtain limited write access to the host filesystem. This issue occurs during the rootfs setup process.
Recommendations Update to version 1.3.6. Update to version 1.4.3. Update to version 1.5.0-rc.3.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91590
CLEANSTART-2026-AS38473
CVE-2026-41579
GHSA-XJVP-4FHW-GC47
GO-2026-5761
OESA-2026-3154
OPENSUSE-SU-2026:11301-1
OPENSUSE-SU-2026:21431-1
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:22938-1
SUSE-SU-2026:22942-1
SUSE-SU-2026:23047-1
SUSE-SU-2026:23164-1
SUSE-SU-2026:3428-1
SUSE-SU-2026:3428-2
SUSE-SU-2026:3433-1
SUSE-SU-2026:3433-2

Affected Products

Runc