Known vulnerabilities in runc
Vendor:
SUSE
Software:
runc
Software CPE:
cpe:2.3:o:suse:runc:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
31
Public exploits:
4
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
1.3.6-150000.101.1
1.3.6-16.76.1
1.3.4-150000.98.1
1.3.4-150000.96.1
1.3.4-150000.94.1
1.3.4-150000.92.1
1.3.4-150000.90.1
1.3.4-16.73.1
1.3.4-150000.88.1
1.3.3-16.70.1
1.3.3-150000.85.1
1.2.7-16.67.1
1.2.7-150000.80.1
1.2.6-16.60.2
1.1.14-16.57.1
1.1.14-16.55.1
1.1.14-150000.70.1
1.1.13-16.52.1
1.1.13-150000.67.1
1.1.12-150000.64.1
1.1.12-150000.61.2
1.1.12-16.46.1
1.1.11-16.43.1
1.1.11-150000.58.1
1.1.10-150000.55.1
1.1.10-16.40.1
1.1.8-150000.49.1
1.1.5-150000.43.1
1.1.5-16.31.1
1.1.5-150000.41.1
1.1.5-16.29.1
1.0.0~rc93-16.11.1
1.0.0~rc93-16.8.1
1.1.3-150000.30.1
1.1.3-16.21.1
1.0.3-27.1
1.0.3-16.18.1
1.0.2-23.1
1.0.2-16.14.1
Vulnerabilities (31)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU134680 - UNIX Symbolic Link (Symlink) Following CVE-2026-41579 |
CWE-61 | Low | 1.3.6-16.76.1, 1.3.6-150000.101.1 | 16.06.2026 |
SB2026061687 SB2026072513 SB2026073105 and 3 more |
||
| #VU118106 - UNIX Symbolic Link (Symlink) Following CVE-2025-52565 |
CWE-61 | Low | 1.2.7-16.67.1, 1.2.7-150000.80.1, 1.3.3-16.70.1, 1.3.3-150000.85.1 | 05.11.2025 |
SB2025110519 SB2025110530 SB2025110545 and 38 more |
||
| #VU118105 - UNIX Symbolic Link (Symlink) Following CVE-2025-52881 |
CWE-61 | Low | 1.2.7-16.67.1, 1.2.7-150000.80.1, 1.3.3-16.70.1, 1.3.3-150000.85.1 | 05.11.2025 |
SB2025110519 SB2025110530 SB2025110545 and 62 more |
||
| #VU118104 - UNIX Symbolic Link (Symlink) Following CVE-2025-31133 |
CWE-61 | Low | 1.2.7-16.67.1, 1.2.7-150000.80.1, 1.3.3-16.70.1, 1.3.3-150000.85.1 | 05.11.2025 |
SB2025110519 SB2025110530 SB2025110545 and 34 more |
||
| #VU96712 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2024-45310 |
CWE-362 | Low | 1.1.14-16.55.1, 1.1.14-150000.70.1, 1.2.6-16.60.2 | 03.09.2024 |
SB2024090315 SB2024091283 SB2024091416 and 18 more |
||
| #VU85991 - Security Features CVE-2024-21626 |
CWE-254 | High | 1.1.11-16.43.1, 1.1.11-150000.58.1, 1.1.12-16.46.1, 1.1.12-150000.61.2 | 01.02.2024 |
SB2024020112 SB2024020113 SB2024020123 and 78 more |
||
| #VU74193 - Improper preservation of permissions CVE-2023-28642 |
CWE-281 | Medium | 1.1.5-16.29.1, 1.1.5-150000.41.1 | 30.03.2023 |
SB2023033025 SB2023040327 SB2023042614 and 29 more |
||
| #VU74190 - Improper Access Control CVE-2023-27561 |
CWE-284 | Low | 1.1.5-16.29.1, 1.1.5-150000.41.1 | 30.03.2023 |
SB2023033025 SB2023040327 SB2023042614 and 40 more |
||
| #VU74189 - Improper preservation of permissions CVE-2023-25809 |
CWE-281 | Low | 1.1.5-16.29.1, 1.1.5-150000.41.1 | 30.03.2023 |
SB2023033025 SB2023040327 SB2023042614 and 23 more |
||
| #VU66447 - Overly Permissive Cross-domain Whitelist CVE-2022-1996 |
CWE-942 | Low | 1.1.10-150000.55.1 | 12.08.2022 |
SB2022081216 SB2022081228 SB2022081229 and 65 more |
||
| #VU64417 - Exposure of sensitive information to an unauthorized actor CVE-2021-41092 |
CWE-200 | Medium | 1.0.2-16.14.1, 1.0.2-23.1 | 15.06.2022 |
SB2021100420 SB2022061528 SB2021101264 and 13 more |
||
| #VU64007 - Resource exhaustion CVE-2022-31030 |
CWE-400 | Medium | 1.1.3-16.21.1, 1.1.3-150000.30.1 | 07.06.2022 |
SB2022060702 SB2022061206 SB2022061326 and 23 more |
||
| #VU63090 - Permissions, Privileges, and Access Controls CVE-2022-29162 |
CWE-264 | Medium | 1.1.3-16.21.1, 1.1.3-150000.30.1 | 12.05.2022 |
SB2022051205 SB2022062435 SB2022071158 and 32 more |
||
| #VU58522 - Integer overflow CVE-2021-43784 |
CWE-190 | Medium | 1.0.3-16.18.1, 1.0.3-27.1 | 06.12.2021 |
SB2021120604 SB2021121497 SB2021122314 and 11 more |
||
| #VU57038 - Incorrect Default Permissions CVE-2021-41103 |
CWE-276 | Low | 1.0.2-16.14.1, 1.0.2-23.1 | 04.10.2021 |
SB2021100406 SB2021100503 SB2021110812 and 21 more |
||
| #VU54999 - Permissions, Privileges, and Access Controls CVE-2021-32760 |
CWE-264 | Medium | 1.0.2-16.14.1, 1.0.2-23.1 | 20.07.2021 |
SB2021072005 SB2021072227 SB2021072708 and 17 more |
||
| #VU48373 - Exposure of sensitive information to an unauthorized actor CVE-2020-12912 |
CWE-200 | Low | 1.1.10-16.40.1 | 11.11.2020 |
SB2020111118 SB2023120115 SB2023121950 and 4 more |
||
| #VU48372 - Observable Response Discrepancy CVE-2020-8695 |
CWE-204 | Low | 1.1.10-16.40.1 | 11.11.2020 |
SB2020111117 SB2020112423 SB2020112424 and 35 more |
||
| #VU48371 - Improper Access Control CVE-2020-8694 |
CWE-284 | Low | 1.1.10-16.40.1 | 11.11.2020 |
SB2020111117 SB2023120115 SB2023121950 and 9 more |
||
| #VU25847 - Improper Access Control CVE-2019-19921 |
CWE-284 | Low | 1.0.0~rc93-16.8.1, 1.1.5-16.29.1, 1.1.5-150000.41.1 | 10.03.2020 |
SB2020021224 SB2020031004 SB2020031116 and 35 more |
Showing elements 1 - 20 out of 31