<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:41:11.742916+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:0670</id>
    <title>ALSA-2024:0670 — Important: runc security update</title>
    <updated>2026-10-02T11:41:12.438939+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: runc</p>
<p>The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.</p>
<p>Security Fix(es):</p>
<p>* runc: file descriptor leak (CVE-2024-21626)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:0670"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-00973</id>
    <title>bdu:2024-00973</title>
    <updated>2026-10-02T11:41:12.439017+00:00</updated>
    <content>bdu:2024-00973</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-00973"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-21626</id>
    <title>BELL-CVE-2024-21626</title>
    <updated>2026-10-02T11:41:12.439036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: runc, Alpaquita:stream: runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-21626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0459</id>
    <title>certfr-2024-avi-0459 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T11:41:12.439057+00:00</updated>
    <content>certfr-2024-avi-0459</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cy16593</id>
    <title>CLEANSTART-2026-CY16593 — Security fix for CVE-2024-21626 applied in: runc 1.1.12-r0</title>
    <updated>2026-10-02T11:41:12.439073+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: runc</p>
<p>Security vulnerability affects the runc package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cy16593"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2024:0027</id>
    <title>ESSA-2024:0027 — security update for runc</title>
    <updated>2026-10-02T11:41:12.439093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>security update for runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2024:0027"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-370201</id>
    <title>EUVD-2026-370201</title>
    <updated>2026-10-02T11:41:12.439110+00:00</updated>
    <content>EUVD-2026-370201</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-370201"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-21626</id>
    <title>fkie_cve-2024-21626</title>
    <updated>2026-10-02T11:41:12.439121+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-21626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xr7r-f8xq-vfvv</id>
    <title>GHSA-xr7r-f8xq-vfvv — runc vulnerable to container breakout through process.cwd trickery and leaked fds</title>
    <updated>2026-10-02T11:41:12.439147+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/opencontainers/runc</p>
<p>### Impact</p>
<p>In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from `runc exec`) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through `runc run` ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b").</p>
<p>Strictly speaking, while attack 3a is the most severe from a CVSS perspective, attacks 2 and 3b are arguably more dangerous in practice because they allow for a breakout from inside a container as opposed to requiring a user execute a malicious image. The reason attacks 1 and 3a are scored higher is because being able to socially engineer users is treated as a given for UI:R vectors, despite attacks 2 and 3b requiring far more minimal user interaction (just reasonable `runc exec` operations on a container the attacker has access to). In any case, all four attacks can lead to full control of the host system.</p>
<p>#### Attack 1: `process.cwd` "mis-configuration"</p>
<p>In runc 1.1.11 and earlier, several file descriptors were inadvertently leaked internally within runc into `runc init`, including a handle to the host's `/sys/fs/cgroup` (this leak was added in v1.0.0-rc93). If…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xr7r-f8xq-vfvv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-21626</id>
    <title>gsd-2024-21626</title>
    <updated>2026-10-02T11:41:12.439233+00:00</updated>
    <content>gsd-2024-21626</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-21626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1182</id>
    <title>OESA-2024-1182 — runc security update</title>
    <updated>2026-10-02T11:41:12.439253+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: runc, openEuler:20.03-LTS-SP4: runc, openEuler:22.03-LTS: runc, openEuler:22.03-LTS-SP1: runc, openEuler:22.03-LTS-SP2: runc, openEuler:22.03-LTS-SP3: runc</p>
<p>runc is a CLI tool for spawning and running containers according to the OCI specification.

Security Fix(es):

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem (&amp;quot;attack 2&amp;quot;). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run (&amp;quot;attack 1&amp;quot;). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes (&amp;quot;attack 3a&amp;quot; and &amp;quot;attack 3b&amp;quot;). runc 1.1.12 includes patches for this issue.(CVE-2024-21626)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1182"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhea-2024:6124</id>
    <title>RHEA-2024:6124 — Red Hat Enhancement Advisory: Red Hat build of MicroShift 4.18.1 security update</title>
    <updated>2026-10-02T11:41:12.439289+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc: file descriptor leak</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhea-2024:6124"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:0294-1</id>
    <title>SUSE-SU-2024:0294-1 — Security update for runc</title>
    <updated>2026-10-02T11:41:12.439306+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:0294-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21626</id>
    <title>UBUNTU-CVE-2024-21626</title>
    <updated>2026-10-02T11:41:12.439321+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: runc, Ubuntu:20.04:LTS: runc, Ubuntu:22.04:LTS: runc</p>
<p>runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-016</id>
    <title>VDE-2024-016 — ADS-TEC Industrial IT: Docker vulnerability affects multiple products</title>
    <updated>2026-10-02T11:41:12.439347+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The affected products and versions present a vulnerability due to a vulnerable integrated software component the docker runc &lt;= 1.1.11. In the worst-case scenario, the integrated Docker container environment could be compromised, potentially enabling the execution of arbitrary code within the Docker environment or neighboring Docker containers if dockerfiles or Docker images from untrusted sources are utilized.</p>
<p>It's crucial to emphasize that while the Docker environment is vulnerable, the host operating system remains
unharmed due to its isolation from the Docker environment within the ads-tec products.</p>
<p>Using Docker images or Dockerfiles from untrusted sources poses a risk. This advice is especially pertinent for Docker use in productive operational technology (OT) environments, and it's our expectation that our customers adhere strictly to this guidance anyway.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-016"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0272</id>
    <title>WID-SEC-W-2024-0272 — docker: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:41:12.439372+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in Docker ausnutzen, um seine Privilegien zu erhöhen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0272"/>
  </entry>
</feed>
