SUSE-SU-2026:23047-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202623047-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23047-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:23047-1
Upstream
Related
Published
2026-08-03T07:15:23Z
Modified
2026-08-12T18:23:40Z
Summary
Security update for runc
Details

This update for runc fixes the following issues:

  • CVE-2026-41579: runc allows a malicious image with a /dev symlink to trigger limited host filesystem integrity violations (bsc#1268275).

Changes for runc:

  • update to 1.3.6:
  • Various integration test improvements. (#5222, #5237, #5226, #5229, #5239, #5249, #5269, #5287, #5295, #5304)
  • When masking directories with maskPaths, runc will now re- use a single tmpfs instance (which is not writeable) to reduce the number tmpfs superblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly).
  • update to 1.3.5
  • Recursive atime-related mount flags (rrelatime et al.) are now applied properly. (#5115, #5098)
  • PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when running runc create and has thus been reverted. (#5158, #5153, #5151, #4645, #4757)
  • Updated builds to Go 1.25, libseccomp v2.6.0. (#5111, #5053)
  • Minor signing keyring updates. (#5146, #5139, #5144, #5148)
References

Affected packages

SUSE:Linux Micro 6.0 / runc

Package

Name
runc
Purl
pkg:rpm/suse/runc&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.6-1.1

Ecosystem specific

{
    "binaries":  [
        {
            "runc":  "1.3.6-1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23047-1.json"