#1140000 runc: CVE-2026-41579

Package:
src:runc
Source:
src:runc
Submitter:
Salvatore Bonaccorso
Date:
2026-08-06 11:51:03 UTC
Severity:
normal
Tags:
#1140000#5
Date:
2026-06-14 13:50:07 UTC
From:
To:
Hi,

The following vulnerability was published for runc.

CVE-2026-41579[0]:
| runc allows a malicious image with a /dev symlink to trigger limited
| host filesystem integrity violations

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-41579
https://www.cve.org/CVERecord?id=CVE-2026-41579
[1] https://www.openwall.com/lists/oss-security/2026/06/13/2
[2] https://github.com/opencontainers/runc/security/advisories/GHSA-xjvp-4fhw-gc47
[3] https://github.com/opencontainers/runc/commit/864db8042dbb191028676f80addf8c35f348aee2

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1140000#10
Date:
2026-08-06 11:49:14 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
runc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140000@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Reinhard Tartler <siretart@tauware.de> (supplier of updated runc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 06 Aug 2026 13:33:30 +0200
Source: runc
Architecture: source
Version: 1.3.6+ds1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Changed-By: Reinhard Tartler <siretart@tauware.de>
Closes: 1046528 1140000
Changes:
 runc (1.3.6+ds1-1) unstable; urgency=medium
 .
   * New upstream release
   * Fixes CVE-2026-41579: a malicious image with a /dev symlink could
     cause limited host filesystem integrity violations (Closes: #1140000)
   * Fix a regression in v1.3.0 that could result in a stuck `runc exec`
     or `runc run` when the container process runs for a short time
   * Reuse a single read-only tmpfs when masking directories, reducing
     tmpfs superblock churn (relevant for Kubernetes per-CPU sysfs masks)
   * debian/clean: clean up generated man pages so that the source
     package can be built again after a successful build (Closes: #1046528)
   * Bump Standards Version, drop Priority: optional
Checksums-Sha1:
 0d5cbc201532789dff8cf7cbdcc3f15cfa61e5c5 3464 runc_1.3.6+ds1-1.dsc
 1235fa0071e850008f616e726e790cf946f88831 521740 runc_1.3.6+ds1.orig.tar.xz
 da436d31ece9d9eaf4ded131c73af32d863baa3a 13596 runc_1.3.6+ds1-1.debian.tar.xz
Checksums-Sha256:
 a7eff082067a6914a2b6f8bdc53a9d13dc29a092804750214dceaddbc35b6769 3464 runc_1.3.6+ds1-1.dsc
 008c1386c4e36cedf0f4a8c1e74da3d0dfc6789f73e166b8b8df5f107ac5edb8 521740 runc_1.3.6+ds1.orig.tar.xz
 22aaf23f2b2cd43f7107d77352ebabf1b11d2cc602ca19964f408b2b72a1b1ff 13596 runc_1.3.6+ds1-1.debian.tar.xz
Files:
 241ad55055e0f9f707720b876e474572 3464 admin optional runc_1.3.6+ds1-1.dsc
 971970016cd35763fa2374f65a4de61c 521740 admin optional runc_1.3.6+ds1.orig.tar.xz
 d32b82fe9521121624ac47f4b4afa8a2 13596 admin optional runc_1.3.6+ds1-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQJIBAEBCgAyFiEEMN59F2OrlFLH4IJQSadpd5QoJssFAmp0cZwUHHNpcmV0YXJ0
QHRhdXdhcmUuZGUACgkQSadpd5QoJsslZA/+MUowzpgf51NuiYYAJv0oJVWiIhgZ
U8Z+R0XhfqCDsNekW58dmPkrEkktQYZa5CgQlVYglVBrjSoWWM7tHFWHz9Me7eh+
mObETnTlNxyxQ6gBejc69LKPUE4lFedLDK1BaTvNegPUvXvmZO7fdWBAZn4Aaqsf
Eetd8hf3xHmoUbWH7WuPGCfiptXb3s6kuxmQkBcrXKvvkT8rcZnFdcoPPdAC2an4
tw42bRA9MTZAnahG1C5nfzYu90bOIgNKVldQ2f1j5+vhsQVH93bB/GhPkkgp631b
hs3oERPJWDT34OUT8V6I2wjrktLSRa73w0//p7vdX1oft93Ce2vh2z4xntc+DgoP
56RPydvzbgtGEXuKBR5xnm2oL3kUtVTBeQU1yBQgKKFP+t8CERY+Q4p0wKVDbkSz
IT04aPA+P3qM8UDao3LNhhMBKIPVOiKsI4XQgPsbOu2JlT2mZuRok4HtvQvxOtdR
Yj+zdtIBvTU6rRjeY5fnfhV4W5Yf8IJvNzurSSVrVYEHqF8b7Jr0tdz+pd8ogkKU
u+OzHKJLplcBIJHH0VA46yMcmBhSnWZhKXYSvkwtNgPsoQx8CEzWWhuWZ/5LM9Cr
7Bm2CdjDLDjpG9eWSG4MwQg6EECdx2t0vr5wEC04fd6RABwA9tYM9Fu84NwqV1ce
+TL7OdAz8z1Fwac=
=Lm/m
-----END PGP SIGNATURE-----