boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2024-21626HIGH
opencontainers runc — runc container breakout through process.cwd trickery and leaked fds
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  C  H  H  H    8.6   .1809   97.0     —
AFFECTED
  Product  Versions                   Fixed
  runc     >=v1.0.0-rc93, < 1.1.12 –  —
TIMELINE
  Dec 29  Reserved by GitHub_M
  Jan 31  Published (CNA: GitHub_M)
  Aug 18  EXPLOIT PUBLISHED — CVE-2024-21626 (opencontainers runc). Public exploit reference added.
CWE-403, CWE-668, CWE-200 · CNA: GitHub_M · CVSS v3.1 · 40 references · NVD status: Modified

Description

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
December 29, 2023ReservedReserved by GitHub_M
January 31, 2024PublishedPublished (CNA: GitHub_M)
August 18, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2024-21626 (opencontainers runc). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
opencontainersrunc>=v1.0.0-rc93, < 1.1.12

Weaknesses

CWE-403 · CWE-668 · CWE-200

References (40)

Related

Authoritative record: CVE-2024-21626 at cve.org

Vendors: opencontainers

Weaknesses: CWE-403 · CWE-668 · CWE-200

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-21626 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.