Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3433-2

Опубликовано: 10 авг. 2026
Источник: suse-cvrf

Описание

Security update for runc

This update for runc fixes the following issues:

Update to 1.3.6.

  • CVE-2026-41579: malicious image with a /dev symlink can trigger limited host filesystem integrity violations (bsc#1268275).

Other updates and bugfixes:

  • Version 1.3.6:
    • When masking directories with maskPaths, runc will now re- use a single tmpfs instance (which is not writeable) to reduce the number tmpfs superblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly).
  • Version 1.3.5:
    • Recursive atime-related mount flags (rrelatime et al.) are now applied properly.
    • PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when running runc create and has thus been reverted.
    • Updated builds to Go 1.25, libseccomp v2.6.0.
    • Minor signing keyring updates.

Список пакетов

Container suse/sle-micro/5.5:latest
runc-1.3.6-150000.101.1
Image SLES15-SP6
runc-1.3.6-150000.101.1
Image SLES15-SP6-BYOS
runc-1.3.6-150000.101.1
Image SLES15-SP6-BYOS-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP6-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP6-Hardened-BYOS
runc-1.3.6-150000.101.1
Image SLES15-SP6-Hardened-BYOS-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-Azure
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-Azure-3P
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-BYOS
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-BYOS-Azure
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-BYOS-EC2
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-BYOS-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-EC2
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-Hardened
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-Hardened-Azure
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-Hardened-BYOS
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-Hardened-BYOS-Azure
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-Hardened-BYOS-EC2
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-Hardened-BYOS-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-Hardened-EC2
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAP-Hardened-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAPCAL
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAPCAL-Azure
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAPCAL-EC2
runc-1.3.6-150000.101.1
Image SLES15-SP6-SAPCAL-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP7-BYOS-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP7-CHOST-BYOS-Aliyun
runc-1.3.6-150000.101.1
Image SLES15-SP7-CHOST-BYOS-Azure
runc-1.3.6-150000.101.1
Image SLES15-SP7-CHOST-BYOS-EC2
runc-1.3.6-150000.101.1
Image SLES15-SP7-CHOST-BYOS-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP7-CHOST-BYOS-GDC
runc-1.3.6-150000.101.1
Image SLES15-SP7-CHOST-BYOS-SAP-CCloud
runc-1.3.6-150000.101.1
Image SLES15-SP7-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP7-Hardened-BYOS-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAP-Azure
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAP-Azure-3P
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAP-BYOS-Azure
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAP-BYOS-EC2
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAP-BYOS-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAP-EC2
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAP-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAP-Hardened-Azure
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAP-Hardened-BYOS-Azure
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAP-Hardened-BYOS-EC2
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAP-Hardened-BYOS-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAP-Hardened-GCE
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAPCAL-Azure
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAPCAL-EC2
runc-1.3.6-150000.101.1
Image SLES15-SP7-SAPCAL-GCE
runc-1.3.6-150000.101.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
runc-1.3.6-150000.101.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
runc-1.3.6-150000.101.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
runc-1.3.6-150000.101.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
runc-1.3.6-150000.101.1
SUSE Linux Enterprise Server 15 SP4-LTSS
runc-1.3.6-150000.101.1
SUSE Linux Enterprise Server 15 SP5-LTSS
runc-1.3.6-150000.101.1
SUSE Linux Enterprise Server 15 SP6-LTSS
runc-1.3.6-150000.101.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
runc-1.3.6-150000.101.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
runc-1.3.6-150000.101.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
runc-1.3.6-150000.101.1

Описание

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string which allow an image with /dev as a symlink to trick runc into deleting files called ptmx on the host or creating a hardcoded set of symlinks with specific names and targets in an arbitrary pre-existing host directory. This issue is not exploitable under Docker, because Docker creates a top-level read-only layer that masks any malicious /dev symlink present in the container image - unlike some other Linux container tooling, whose higher-level runtimes built on runc remain exposed to exploitation via a malicious image. This issue has been fixed in versions 1.3.6, 1.4.3 and 1.5.0.


Затронутые продукты
Container suse/sle-micro/5.5:latest:runc-1.3.6-150000.101.1
Image SLES15-SP6-BYOS-GCE:runc-1.3.6-150000.101.1
Image SLES15-SP6-BYOS:runc-1.3.6-150000.101.1
Image SLES15-SP6-GCE:runc-1.3.6-150000.101.1

Ссылки