{"id":"DEBIAN-CVE-2026-41579","details":"runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string which allow an image with /dev as a symlink to trick runc into deleting files called ptmx on the host or creating a hardcoded set of symlinks with specific names and targets in an arbitrary pre-existing host directory. This issue is not exploitable under Docker, because Docker creates a top-level read-only layer that masks any malicious /dev symlink present in the container image — unlike some other Linux container tooling, whose higher-level runtimes built on runc remain exposed to exploitation via a malicious image. This issue has been fixed in versions 1.3.6, 1.4.3 and 1.5.0.","modified":"2026-09-14T17:03:11.755694315Z","published":"2026-07-01T02:17:00.193Z","upstream":["CVE-2026-41579"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-41579"}],"affected":[{"package":{"name":"runc","ecosystem":"Debian:12","purl":"pkg:deb/debian/runc?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.10+ds1-1","1.1.12+ds1-1","1.1.12+ds1-2","1.1.12+ds1-3","1.1.12+ds1-4","1.1.12+ds1-5","1.1.12+ds1-5.1","1.1.15+ds1-1","1.1.15+ds1-2","1.1.5+ds1-1","1.1.5+ds1-1+deb12u1","1.1.5+ds1-2","1.1.5+ds1-3","1.1.5+ds1-4","1.1.5+ds1-5","1.3.0+ds1-1","1.3.0+ds1-2","1.3.0+ds1-3","1.3.0+ds1-4","1.3.2+ds1-1","1.3.3+ds1-1","1.3.3+ds1-2","1.3.3+ds1-3","1.3.5+ds1-1","1.3.6+ds1-1","1.4.3+ds1-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41579.json"}},{"package":{"name":"runc","ecosystem":"Debian:13","purl":"pkg:deb/debian/runc?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.15+ds1-2","1.3.0+ds1-1","1.3.0+ds1-2","1.3.0+ds1-3","1.3.0+ds1-4","1.3.2+ds1-1","1.3.3+ds1-1","1.3.3+ds1-2","1.3.3+ds1-3","1.3.5+ds1-1","1.3.6+ds1-1","1.4.3+ds1-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41579.json"}},{"package":{"name":"runc","ecosystem":"Debian:14","purl":"pkg:deb/debian/runc?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.6+ds1-1"}]}],"versions":["1.1.15+ds1-2","1.3.0+ds1-1","1.3.0+ds1-2","1.3.0+ds1-3","1.3.0+ds1-4","1.3.2+ds1-1","1.3.3+ds1-1","1.3.3+ds1-2","1.3.3+ds1-3","1.3.5+ds1-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41579.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}