CVE-2019-5736
HIGH 9.3EPSS 98.5%
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
- CVSS v3.1
- 8.6 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H - CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 98.45% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2019-02-11
- Updated
- 2024-08-04
Proof-of-concept exploits (58)
- http://packetstormsecurity.com/files/163339/Docker-Container-Escape.html
- http://packetstormsecurity.com/files/165197/Docker-runc-Command-Execution-Proof-Of-Concep…
- https://blog.dragonsector.pl/2019/02/cve-2019-5736-escape-from-docker-and.html
- Frichetten/CVE-2019-5736-PoC658★ · 2022-01-05
- q3k/cve-2019-5736-poc210★ · 2019-02-20
- https://support.mesosphere.com/s/article/Known-Issue-Container-Runtime-Vulnerability-MSPH…
- BBRathnayaka/POC-CVE-2019-57360★ · 2020-05-14
- Billith/CVE-2019-5736-PoC0★ · 2020-05-03
- BurlakaR/tpc0★ · 2020-05-17
- C2ActiveThreatHunters/Awesome-Docker-Kubernetis-Containers-Vulnerabilities-and-Exploitati…0★ · 2022-08-05
- GiverOfGifts/CVE-2019-5736-Custom-Runtime1★ · 2020-02-20
- H3xL00m/CVE-2019-57360★ · 2025-06-05
- HoangLai2k3/CVE_2019_57360★ · 2024-05-19
- JlSakuya/CVE-2022-0847-container-escape2★ · 2023-04-26
- Keramas/Blowhole22★ · 2019-10-07
- Laihoang2k3/CVE_2019_57360★ · 2024-05-19
- Lee-SungYoung/cve-2019-5736-study0★ · 2019-08-05
- N3rdyN3xus/CVE-2019-57360★ · 2025-06-05
- NyxByt3/CVE-2019-57360★ · 2025-06-05
- Perimora/cve_2019-5736-PoC0★ · 2025-06-25
- RyanNgWH/CVE-2019-5736-POC0★ · 2019-06-30
- ShadowFl0w/Cloud-Native-Security-Test8★ · 2022-06-03
- Sp3c73rSh4d0w/CVE-2019-57360★ · 2025-06-05
- agppp/cve-2019-5736-poc7★ · 2019-02-15
- aishee/DOCKER-2019-57360★ · 2019-02-18
- b3d3c/poc-cve-2019-57361★ · 2019-02-19
- c0d3cr4f73r/CVE-2019-57360★ · 2025-06-05
- chosam2/cve-2019-5736-poc0★ · 2019-11-16
- colin-404/Cloud-Native-Security-Test8★ · 2022-06-03
- crypticdante/CVE-2019-57360★ · 2025-06-05
- epsteina16/Docker-Escape-Miner3★ · 2019-12-12
- fahmifj/Docker-breakout-runc0★ · 2021-08-07
- geropl/CVE-2019-57360★ · 2020-01-08
- h3x0v3rl0rd/CVE-2019-57360★ · 2025-06-05
- h3xcr4ck3r/CVE-2019-57360★ · 2025-06-05
- jas502n/CVE-2019-573614★ · 2019-02-14
- k4u5h41/CVE-2019-57360★ · 2025-06-05
- kindredgroupsec/venom0★ · 2019-10-21
- likekabin/CVE-2019-57361★ · 2019-02-14
- likekabin/cve-2019-5736-poc0★ · 2019-02-14
- likescam/CVE-2019-57361★ · 2019-02-14
- likescam/cve-2019-5736-poc0★ · 2019-02-14
- milloni/cve-2019-5736-exp1★ · 2019-04-14
- n3ov4n1sh/CVE-2019-57360★ · 2025-06-05
- n3rdh4x0r/CVE-2019-57360★ · 2025-06-05
- panzouh/Docker-Runc-Exploit1★ · 2021-12-08
- runerx/Cloud-Native-Security-Test8★ · 2022-06-03
- saucer-man/exploit11★ · 2021-07-09
- si1ent-le/CVE-2019-57360★ · 2022-03-16
- sonyavalo/CVE-2019-5736-Dockerattack-and-security-mechanism0★ · 2024-11-28
- stillan00b/CVE-2019-57360★ · 2019-03-27
- takumak/cve-2019-5736-reproducer0★ · 2022-03-02
- twistlock/RunC-CVE-2019-573686★ · 2020-06-22
- vinci-3000/Cloud-Native-Security-Test8★ · 2022-06-03
- wenxi-3000/Cloud-Native-Security-Test8★ · 2022-06-03
- yyqs2008/CVE-2019-5736-PoC-20★ · 2019-02-23
- h-wookie/cve-2019-5736-poc
- sastraadiwiguna-purpleeliteteaming/Holistic-Deconstruction-of-CVE-2019-5736-