The low-level OCI runtime that actually creates and starts individual containers.
Version: 1.5.2
Type: Runtime
License:
| Expand | CVE | Title | Status | Sev |
|---|---|---|---|---|
| CVE-2025-31133 Open CVE-2025-31133 in a new tab | runc container escape via "masked path" abuse due to mount race conditions | Not affected | Unknown | |
| CVE-2025-52565 Open CVE-2025-52565 in a new tab | container escape due to /dev/console mount and related races | Not affected | Unknown | |
| CVE-2025-52881 Open CVE-2025-52881 in a new tab | runc: LSM labels can be bypassed with malicious config using dummy procfs files | Not affected | Unknown | |
| CVE-2026-41579 Open CVE-2026-41579 in a new tab | runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations | Not affected | Unknown |
runc container escape via "masked path" abuse due to mount race conditions
container escape due to /dev/console mount and related races
runc: LSM labels can be bypassed with malicious config using dummy procfs files
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations