Database/Container, Kubernetes & orchestration
runc: setupPtmx/setupDev rootfs setup flaw during container rootfs construction
CVSS 3.3CVE-2026-41579Container, Kubernetes & orchestrationcurated
Impact
setupPtmx/setupDev rootfs setup flaw during container rootfs construction
Who can reach it
Any tenant workload with crafted rootfs
What to do
Replace runc binary at next maintenance window; low severity, batch with other node work
References
Related entries
- runc: Host runc binary overwritten from inside a containerCVE-2019-5736 · runcHigh
- runc: "Leaky Vessels": internal file descriptor leak lets a container process start with cwd in the host filesystemCVE-2024-21626 · runcHigh
- runc: Container filesystem breakout via directory traversal in mount handlingCVE-2021-30465 · runcHigh
- runc: Insufficient checks when bind-mounting /dev/console allow writes to arbitrary host procfs pathsCVE-2025-52565 · runcHigh
- runc: AppArmor restriction bypass via mount-target check flawCVE-2019-16884 · runcHigh
- runc: Insufficient verification of masked-path bind mounts (/dev/null replaced by symlink) enables containerCVE-2025-31133 · runcHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.