Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-21626— runc container breakout through process.cwd trickery and leaked fds

Quick assessment

Affected
opencontainers runc
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

runc是一款用于根据OCI规范生成和运行容器的CLI(命令行界面)工具。 runc 1.1.12之前版本存在安全漏洞,该漏洞源于fds 内部泄漏,导致多个容器发生泄漏。

CVSS 8.6 · High EPSS 18.92% · P97

Public Exploits 1

Possible ATT&CK Techniques 1 AI

T1610 · Deploy Container

Affected Version Matrix 1

VendorProduct Version RangeStatus
opencontainers runc >=v1.0.0-rc93, < 1.1.12 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-21626

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
runc container breakout through process.cwd trickery and leaked fds
Source: CVE Program / CVE List V5
Vulnerability Description
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
将文件描述符暴露给不受控制的范围(文件描述符泄露)
Source: CVE Program / CVE List V5
Vulnerability Title
runc 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
runc是一款用于根据OCI规范生成和运行容器的CLI(命令行界面)工具。 runc 1.1.12之前版本存在安全漏洞,该漏洞源于fds 内部泄漏,导致多个容器发生泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
opencontainers runc >=v1.0.0-rc93, < 1.1.12 -

II. Public POCs for CVE-2024-21626

# POC Description Source Link Shenlong Link
1 None https://github.com/Wall1e/CVE-2024-21626-POC POC Details
2 PoC and Detection for CVE-2024-21626 https://github.com/NitroCao/CVE-2024-21626 POC Details
3 None https://github.com/zpxlz/CVE-2024-21626-POC POC Details
4 CVE-2024-21626-poc-research-Reappearance-andtodo https://github.com/cdxiaodong/CVE-2024-21626 POC Details
5 None https://github.com/zhangguanzhang/CVE-2024-21626 POC Details
6 Container Runtime Meetup #5 のLT用のデモ https://github.com/laysakura/CVE-2024-21626-demo POC Details
7 None https://github.com/V0WKeep3r/CVE-2024-21626-runcPOC POC Details
8 None https://github.com/abian2/CVE-2024-21626 POC Details
9 None https://github.com/Sk3pper/CVE-2024-21626 POC Details
10 POC https://github.com/KubernetesBachelor/CVE-2024-21626 POC Details
11 None https://github.com/dorser/cve-2024-21626 POC Details
12 None https://github.com/FlojBoj/CVE-2024-21626 POC Details
13 None https://github.com/Sk3pper/CVE-2024-21626-old-docker-versions POC Details
14 Some scripts to simulate an attack (used for CVE-2024-21626) https://github.com/adaammmeeee/little-joke POC Details
15 Root cuase & Proof of cause https://github.com/R4mbb/CVE-2024-21626-PoC POC Details
16 POCs and Tetragon Rules for CVE-2024-21626 and CVE-2025-31133 https://github.com/scherepiuk/container-escape-ebpf POC Details
AI-Generated POC Verified env Premium
Qwen3.6-35B-A3B · 9935 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2024-21626

请登录查看更多情报信息。

Patches & Fixes for CVE-2024-21626 (1)

Vendor Advisories for CVE-2024-21626 (1)

Exploits & Public PoCs for CVE-2024-21626 (1)

Mailing List Discussions for CVE-2024-21626 (5)

Other References for CVE-2024-21626 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-21626

No comments yet


Leave a comment