CVE-2024-21626
HIGH 8.6EPSS 18.1%
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.
- CVSS v3.1
- 8.6 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H - CVSS v3.1
- 8.6 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H - CVSS v3.1
- 8.6 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H - CVSS v3.1
- 8.6 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H - EPSS
- 18.09% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2024-01-31
- Updated
- 2026-08-24
Proof-of-concept exploits (18)
- http://packetstormsecurity.com/files/176993/runc-1.1.11-File-Descriptor-Leak-Privilege-Es…
- FlojBoj/CVE-2024-216261★ · 2024-09-02
- KubernetesBachelor/CVE-2024-216262★ · 2025-05-27
- NitroCao/CVE-2024-2162679★ · 2024-02-06
- R4mbb/CVE-2024-216260★ · 2025-09-09
- R4mbb/CVE-2024-21626-PoC0★ · 2025-09-09
- Sk3pper/CVE-2024-216262★ · 2024-11-10
- Sk3pper/CVE-2024-21626-old-docker-versions0★ · 2024-11-08
- V0WKeep3r/CVE-2024-21626-runcPOC6★ · 2024-02-05
- abian2/CVE-2024-216260★ · 2024-06-03
- cdxiaodong/CVE-2024-216265★ · 2024-02-02
- dorser/cve-2024-216262★ · 2024-04-16
- laysakura/CVE-2024-21626-demo3★ · 2024-02-02
- zhangguanzhang/CVE-2024-216264★ · 2024-02-02
- zpxlz/CVE-2024-21626-POC1★ · 2024-02-01
- Strikoder-Premium/cve-2024-21626-runc-1.1.11-escape
- skysbsb/CVE-2024-21626-POC
- southsidesamurai65-prog/container_all_in_one