runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
{
"unresolved_ranges": [
{
"vendor_product": "d2iq:dc/os",
"cpes": [
"cpe:2.3:o:d2iq:dc\\/os:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "1.10.10"
},
{
"introduced": "1.10.11"
},
{
"fixed": "1.11.9"
}
],
"source": "CPE_RANGE"
},
{
"vendor_product": "d2iq:kubernetes_engine",
"cpes": [
"cpe:2.3:a:d2iq:kubernetes_engine:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "2.2.0-1.13.3"
}
],
"source": "CPE_RANGE"
},
{
"vendor_product": "docker:docker",
"cpes": [
"cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "18.09.2"
},
{
"fixed": "18.09.2"
},
{
"fixed": "18.09.2"
}
],
"source": "CPE_RANGE"
},
{
"vendor_product": "canonical:ubuntu_linux",
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "16.04"
},
{
"last_affected": "16.04"
},
{
"introduced": "18.10"
},
{
"last_affected": "18.10"
},
{
"introduced": "19.04"
},
{
"last_affected": "19.04"
}
],
"source": "CPE_STRING"
},
{
"vendor_product": "fedoraproject:fedora",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "29"
},
{
"last_affected": "29"
},
{
"introduced": "30"
},
{
"last_affected": "30"
}
],
"source": "CPE_STRING"
},
{
"vendor_product": "microfocus:service_management_automation",
"cpes": [
"cpe:2.3:a:microfocus:service_management_automation:2018.02:*:*:*:*:*:*:*",
"cpe:2.3:a:microfocus:service_management_automation:2018.05:*:*:*:*:*:*:*",
"cpe:2.3:a:microfocus:service_management_automation:2018.08:*:*:*:*:*:*:*",
"cpe:2.3:a:microfocus:service_management_automation:2018.11:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "2018.02"
},
{
"last_affected": "2018.02"
},
{
"introduced": "2018.05"
},
{
"last_affected": "2018.05"
},
{
"introduced": "2018.08"
},
{
"last_affected": "2018.08"
},
{
"introduced": "2018.11"
},
{
"last_affected": "2018.11"
}
],
"source": "CPE_STRING"
},
{
"vendor_product": "opensuse:backports_sle",
"cpes": [
"cpe:2.3:a:opensuse:backports_sle:15.0:-:*:*:*:*:*:*",
"cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "15.0-NA"
},
{
"last_affected": "15.0-NA"
},
{
"introduced": "15.0-sp1"
},
{
"last_affected": "15.0-sp1"
}
],
"source": "CPE_STRING"
},
{
"vendor_product": "opensuse:leap",
"cpes": [
"cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "15.0"
},
{
"last_affected": "15.0"
},
{
"introduced": "15.1"
},
{
"last_affected": "15.1"
},
{
"introduced": "42.3"
},
{
"last_affected": "42.3"
}
],
"source": "CPE_STRING"
},
{
"vendor_product": "redhat:container_development_kit",
"cpes": [
"cpe:2.3:a:redhat:container_development_kit:3.7:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "3.7"
},
{
"last_affected": "3.7"
}
],
"source": "CPE_STRING"
},
{
"vendor_product": "redhat:enterprise_linux",
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "8.0"
},
{
"last_affected": "8.0"
}
],
"source": "CPE_STRING"
},
{
"vendor_product": "redhat:enterprise_linux_server",
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "7.0"
},
{
"last_affected": "7.0"
}
],
"source": "CPE_STRING"
},
{
"vendor_product": "redhat:openshift",
"cpes": [
"cpe:2.3:a:redhat:openshift:3.4:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openshift:3.5:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "3.4"
},
{
"last_affected": "3.4"
},
{
"introduced": "3.5"
},
{
"last_affected": "3.5"
}
],
"source": "CPE_STRING"
}
]
}{
"cpe": "cpe:2.3:a:apache:mesos:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "1.4.0"
},
{
"fixed": "1.4.3"
},
{
"introduced": "1.5.0"
},
{
"fixed": "1.5.3"
},
{
"introduced": "1.6.0"
},
{
"fixed": "1.6.2"
},
{
"introduced": "1.7.0"
},
{
"fixed": "1.7.2"
}
],
"source": "CPE_RANGE"
}
{
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"extracted_events": [
{
"introduced": "18.04"
},
{
"last_affected": "18.04"
}
],
"source": [
"CPE_STRING",
"REFERENCES"
]
}
{
"cpe": "cpe:2.3:a:linuxcontainers:lxc:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.2.0"
}
],
"source": "CPE_RANGE"
}
{
"cpe": "cpe:2.3:o:d2iq:dc\\/os:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "1.11.10"
},
{
"fixed": "1.12.1"
}
],
"source": "CPE_RANGE"
}
{
"cpe": [
"cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*",
"cpe:2.3:a:linuxfoundation:runc:1.0.0:rc1:*:*:*:*:*:*",
"cpe:2.3:a:linuxfoundation:runc:1.0.0:rc2:*:*:*:*:*:*",
"cpe:2.3:a:linuxfoundation:runc:1.0.0:rc3:*:*:*:*:*:*",
"cpe:2.3:a:linuxfoundation:runc:1.0.0:rc4:*:*:*:*:*:*",
"cpe:2.3:a:linuxfoundation:runc:1.0.0:rc5:*:*:*:*:*:*",
"cpe:2.3:a:linuxfoundation:runc:1.0.0:rc6:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.1.1"
},
{
"introduced": "1.0.0-rc1"
},
{
"last_affected": "1.0.0-rc1"
},
{
"introduced": "1.0.0-rc2"
},
{
"last_affected": "1.0.0-rc2"
},
{
"introduced": "1.0.0-rc3"
},
{
"last_affected": "1.0.0-rc3"
},
{
"introduced": "1.0.0-rc4"
},
{
"last_affected": "1.0.0-rc4"
},
{
"introduced": "1.0.0-rc5"
},
{
"last_affected": "1.0.0-rc5"
},
{
"introduced": "1.0.0-rc6"
},
{
"last_affected": "1.0.0-rc6"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
]
}
"2026-08-13T08:29:50Z"
[
{
"id": "CVE-2019-5736-1cffac28",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"206209469052802163709281360376397312675",
"48219882597669953983429687793407620753",
"213043235157353488768314210772726520178",
"251821556443359960608428361047721063429",
"93222659505421272286403399172694346479",
"107309039482126281655838517999257961732"
]
},
"source": "https://github.com/opencontainers/runc/commit/0a8e4117e7f715d5fbeef398405813ce8e88558b",
"target": {
"file": "libcontainer/nsenter/nsexec.c"
}
},
{
"id": "CVE-2019-5736-c45baaa5",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 6892.0,
"function_hash": "43249958159973239119332662430070161949"
},
"source": "https://github.com/opencontainers/runc/commit/0a8e4117e7f715d5fbeef398405813ce8e88558b",
"target": {
"function": "nsexec",
"file": "libcontainer/nsenter/nsexec.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5736.json"
{
"cpe": [
"cpe:2.3:a:redhat:openshift:3.6:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openshift:3.7:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "3.6"
},
{
"last_affected": "3.6"
},
{
"introduced": "3.7"
},
{
"last_affected": "3.7"
}
],
"source": "CPE_STRING"
}