Описание
Security update for runc
This update for runc fixes the following issues:
Update to 1.3.6.
- CVE-2026-41579: malicious image with a
/devsymlink can trigger limited host filesystem integrity violations (bsc#1268275).
Other updates and bugfixes:
- Version 1.3.6:
- When masking directories with
maskPaths, runc will now re- use a singletmpfsinstance (which is not writeable) to reduce the numbertmpfssuperblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly).
- When masking directories with
- Version 1.3.5:
- Recursive atime-related mount flags (rrelatime et al.) are now applied properly.
- PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when running runc create and has thus been reverted.
- Updated builds to Go 1.25, libseccomp v2.6.0.
- Minor signing keyring updates.
Список пакетов
SUSE Linux Enterprise Server 12 SP5-LTSS
Ссылки
- Link for SUSE-SU-2026:3428-2
- E-Mail link for SUSE-SU-2026:3428-2
- SUSE Security Ratings
- SUSE Bug 1268275
- SUSE CVE CVE-2026-41579 page
Описание
runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string which allow an image with /dev as a symlink to trick runc into deleting files called ptmx on the host or creating a hardcoded set of symlinks with specific names and targets in an arbitrary pre-existing host directory. This issue is not exploitable under Docker, because Docker creates a top-level read-only layer that masks any malicious /dev symlink present in the container image - unlike some other Linux container tooling, whose higher-level runtimes built on runc remain exposed to exploitation via a malicious image. This issue has been fixed in versions 1.3.6, 1.4.3 and 1.5.0.
Затронутые продукты
Ссылки
- CVE-2026-41579
- SUSE Bug 1268275