<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:39:35.150534+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:0975</id>
    <title>ALSA-2019:0975 — Important: container-tools:rhel8 security and bug fix update</title>
    <updated>2026-10-03T01:39:35.562332+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: oci-systemd-hook, AlmaLinux:8: oci-umount</p>
<p>The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.</p>
<p>Security Fix(es):</p>
<p>* A flaw was found in the way runc handled system file descriptors when running containers. A malicious container could use this flaw to overwrite contents of the runc binary and consequently run arbitrary commands on the container host system. (CVE-2019-5736)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* [stream rhel8] rebase container-selinux to 2.94 (BZ#1693675)</p>
<p>* [stream rhel8] unable to mount disk at `/var/lib/containers` via `systemd` unit when `container-selinux` policy installed (BZ#1695669)</p>
<p>* [stream rhel8] don't allow a container to connect to random services (BZ#1695689)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:0975"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-00826</id>
    <title>bdu:2019-00826</title>
    <updated>2026-10-03T01:39:35.562412+00:00</updated>
    <content>bdu:2019-00826</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-00826"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2019-5736</id>
    <title>Withdrawn: BELL-CVE-2019-5736 — CVE-2019-5736 does not affect BellSoft software</title>
    <updated>2026-10-03T01:39:35.562430+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2019-5736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2019-avi-070</id>
    <title>certfr-2019-avi-070 — Une vulnérabilité a été découverte dans les produits VMware. Elle permet
à un attaquant de provoquer une exécution de c…</title>
    <updated>2026-10-03T01:39:35.562445+00:00</updated>
    <content>certfr-2019-avi-070</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2019-avi-070"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-20190215-runc</id>
    <title>cisco-sa-20190215-runc — Container Privilege Escalation Vulnerability Affecting Cisco Products: February 2019</title>
    <updated>2026-10-03T01:39:35.562459+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the Open Container Initiative runc CLI tool used by multiple products could allow an unauthenticated, remote attacker to escalate privileges on a targeted system.

The vulnerability exists because the affected software improperly handles file descriptors related to /proc/self/exe. An attacker could exploit the vulnerability either by persuading a user to create a new container using an attacker-controlled image or by using the docker exec command to attach into an existing container that the attacker already has write access to. A successful exploit could allow the attacker to overwrite the host's runc binary file with a malicious file, escape the container, and execute arbitrary commands with root privileges on the host system.

This advisory will be updated as additional information becomes available.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190215-runc ["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190215-runc"]</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-20190215-runc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bp85403</id>
    <title>CLEANSTART-2026-BP85403 — Security fix for CVE-2019-5736 applied in: runc 1.0.0_rc7-r0</title>
    <updated>2026-10-03T01:39:35.562486+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: runc</p>
<p>Security vulnerability affects the runc package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bp85403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-50405</id>
    <title>EUVD-2026-50405</title>
    <updated>2026-10-03T01:39:35.562505+00:00</updated>
    <content>EUVD-2026-50405</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-50405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-5736</id>
    <title>fkie_cve-2019-5736</title>
    <updated>2026-10-03T01:39:35.562516+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-5736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gxmr-w5mj-v8hh</id>
    <title>GHSA-gxmr-w5mj-v8hh</title>
    <updated>2026-10-03T01:39:35.562539+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gxmr-w5mj-v8hh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-5736</id>
    <title>gsd-2019-5736</title>
    <updated>2026-10-03T01:39:35.562566+00:00</updated>
    <content>gsd-2019-5736</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-5736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2019-5736</id>
    <title>msrc_CVE-2019-5736 — runc through 1.0-rc6 as used in Docker before 18.09.2 and other products allows attackers to overwrite the host runc bi…</title>
    <updated>2026-10-03T01:39:35.562577+00:00</updated>
    <content>msrc_CVE-2019-5736</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2019-5736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2019:0252-1</id>
    <title>openSUSE-SU-2019:0252-1 — Security update for docker-runc</title>
    <updated>2026-10-03T01:39:35.562594+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for docker-runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2019:0252-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2019:0303</id>
    <title>RHSA-2019:0303 — Red Hat Security Advisory: runc security update</title>
    <updated>2026-10-03T01:39:35.562609+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc: Execution of malicious containers allows for container escape and access to host filesystem</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2019:0303"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2019:0362-1</id>
    <title>SUSE-SU-2019:0362-1 — Security update for docker-runc</title>
    <updated>2026-10-03T01:39:35.562624+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for docker-runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2019:0362-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-5736</id>
    <title>UBUNTU-CVE-2019-5736</title>
    <updated>2026-10-03T01:39:35.562637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: docker.io, Ubuntu:16.04:LTS: runc, Ubuntu:18.04:LTS: docker.io, Ubuntu:18.04:LTS: runc</p>
<p>runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-5736"/>
  </entry>
</feed>
