github.com/OpenContainers/runc
Security Advisories for github.com/OpenContainers/runc in go
Moderate
about 2 months ago
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
go
github.com/opencontainers/runc
Potential
High
10 months ago
youki container escape and denial of service due to arbitrary write gadgets and procfs write redirects
cargo
youki
Potential
High
10 months ago
youki container escape via "masked path" abuse due to mount race conditions
cargo
youki
High
10 months ago
runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects
go
github.com/opencontainers/runc
High
10 months ago
runc container escape with malicious config due to /dev/console mount and related races
go
github.com/opencontainers/runc
High
10 months ago
runc container escape via "masked path" abuse due to mount race conditions
go
github.com/opencontainers/runc
Potential
Moderate
over 1 year ago
Libcontainer is affected by capabilities elevation similar to GHSA-f3fp-gc8g-vw66
cargo
libcontainer
Moderate
almost 2 years ago
runc can be confused to create empty files/directories on the host
go
github.com/opencontainers/runc
High
over 2 years ago
runc vulnerable to container breakout through process.cwd trickery and leaked fds
go
github.com/opencontainers/runc
Moderate
over 3 years ago
runc AppArmor bypass with symlinked /proc
go
github.com/opencontainers/runc
Low
over 3 years ago
rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runc
go
github.com/opencontainers/runc
High
over 3 years ago
Opencontainers runc Incorrect Authorization vulnerability
go
github.com/opencontainers/runc
Moderate
about 4 years ago
Default inheritable capabilities for linux container should be empty
go
github.com/opencontainers/runc
High
over 4 years ago
Incorrect Authorization in runc
go
github.com/opencontainers/selinux, github.com/opencontainers/runc
Low
over 4 years ago
devices resource list treated as a blacklist by default
go
github.com/opencontainers/runc
Moderate
over 4 years ago
Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC
go
github.com/opencontainers/runc
Moderate
about 5 years ago
opencontainers runc contains procfs race condition with a shared volume mount
go
github.com/opencontainers/runc
High
about 5 years ago
mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs
go
github.com/opencontainers/runc