Several distinct runc vulnerabilities can weaken container isolation, and some attack paths can reach or affect the host. They are not one universal Docker exploit: each CVE has different prerequisites and impacts, and one 2026 issue is specifically described by the runc project as not exploitable under Docker. Identify the CVE, check your vendor’s package advisory, and install its supported fix.
What the runC flaws mean for Docker
runc is a low-level container runtime used beneath higher-level container tools, including Docker. A flaw in it can therefore create an escape path—but exposure depends on the vulnerability, runtime configuration, and how a container is created or run. “Root access” in this context means a particular attack may cross the container boundary and affect the host with elevated privileges; it does not mean every vulnerable container automatically gives an attacker host root.
The issues below are separate CVEs, not interchangeable descriptions of one bug. The OpenContainers/runc advisories describe the technical conditions; Docker’s advisory and announcements establish Docker-specific applicability where noted. The facts here reflect those advisories as of October 4, 2026.
Which CVEs are involved, and how do they differ?
| CVE | Prerequisite or condition | Attack mechanism and possible impact | Docker applicability | Version or fix information in the advisories |
|---|---|---|---|---|
| CVE-2024-21626 | A malicious image, or a controlled runc exec working-directory path; the attack depends on the described working-directory conditions. |
Leaked internal file descriptors and a host-namespace working directory can expose host files; variants can overwrite host binaries. | Docker’s advisory describes exposure through a malicious image or specific workdir options, including Dockerfiles. It is not an attack on every running container. | OpenContainers/runc identifies 1.1.11 and earlier as affected. The advisory describes fixes that verify the final working directory is inside the container and close or correct leaked descriptors. |
| CVE-2025-31133 | Relevant mount-race and masking conditions described in the runc advisory. |
A race involving /dev/null masking can give a container writable access to a procfs target. Under the relevant conditions, writing /proc/sys/kernel/core_pattern can route execution through a host-privileged coredump helper. A separate masked-path bypass can reveal information normally hidden. |
The advisory describes attacks relevant to container runtimes; assess the actual Docker and host configuration rather than assuming every Docker workload is exposed. | OpenContainers/runc lists 1.2.8, 1.3.3, and 1.4.0-rc.3 as fixed. It says 1.1.x and earlier are unsupported and were not patched for this issue. A complete affected range is not stated in that advisory information. |
| CVE-2025-52565 | The described attack depends on the ordering of a /dev/console bind mount and subsequent masked and read-only path handling. |
A container may gain write access to procfs targets such as /proc/sysrq-trigger or /proc/sys/kernel/core_pattern, potentially causing denial of service or a container breakout in the described configuration. |
The runc advisory describes a container-runtime risk; exact exposure depends on the configuration and any chained flaws. |
A fixed-version range is not stated in the advisory information summarized here. Check the applicable vendor security notice and package changelog. |
| CVE-2025-52881 | A racing container with shared mounts. The runc project verified a possible route involving parallel docker buildx build execution with custom shared mounts. |
Racing writes redirected to procfs can undermine isolation. This does not establish that ordinary Dockerfile builds automatically trigger the issue. | Docker Buildx is relevant only in the described concurrent-build and custom-shared-mount scenario; do not generalize that finding to all builds. | A fixed-version range is not stated in the advisory information summarized here. Check the applicable vendor security notice and package changelog. |
| CVE-2026-41579 | A malicious image uses /dev as a symlink. |
The runc advisory describes limited host-filesystem integrity violations. |
The upstream advisory says this issue is not exploitable under Docker: Docker masks the symlink with a top-level read-only layer. Applicability differs among runtimes. | A fixed-version range is not stated in the advisory information summarized here. Check the applicable runtime or distribution notice. |
How the attack paths work
CVE-2024-21626: leaked descriptors and working directories
In affected runc versions, internal file descriptors could leak into the container init process. The advisory’s attack path uses a working directory that resolves into a host namespace; a malicious image or a controlled runc exec workdir can exploit that condition to reach host files. Some variants can overwrite host binaries. Docker’s advisory also describes exposure through specific workdir options, including options used in Dockerfiles. This is a conditional escape path, not evidence that simply running any container causes a host compromise.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
CVE-2025-31133 and CVE-2025-52565: procfs writes
These CVEs involve different mount-handling flaws, but both advisories describe ways that a container may obtain write access to sensitive procfs paths. The affected paths and outcomes are not identical: CVE-2025-31133 includes a /dev/null masking race and a separate information-disclosure variant, while CVE-2025-52565 concerns the timing of the /dev/console bind mount relative to masked and read-only paths. A successful write to a sensitive target can have serious consequences, including denial of service or, under the stated conditions, a route to host-privileged execution.
CVE-2025-52881: redirected writes during concurrent builds
The runc project’s verified possible route involves containers racing while mounts are shared, including parallel docker buildx build execution with custom shared mounts. The custom mount and concurrency details matter. The advisory does not say that a routine single Docker build, without those conditions, automatically exposes the host.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
CVE-2026-41579: a runtime-specific exception
A malicious image that makes /dev a symlink can cause limited host-filesystem integrity violations through runc, according to the upstream advisory. The same advisory says Docker prevents exploitation of this particular issue by masking the symlink with a top-level read-only layer. That Docker-specific conclusion should not be assumed for other runtimes.
Which versions are affected, and how should you patch?
For CVE-2024-21626, the runc advisory identifies versions 1.1.11 and earlier as affected. For CVE-2025-31133, it lists 1.2.8, 1.3.3, and 1.4.0-rc.3 as fixed, while stating that 1.1.x and earlier are unsupported and were not patched for that issue. The advisory details available for the other CVEs above do not establish their full affected ranges or fixed versions, so do not infer them from these figures.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
Use your operating system or runtime vendor’s security notice to determine whether the package installed on your host contains the fix. Distributions may backport patches without changing the upstream version string to the listed fixed version. Conversely, a version number alone is not proof that a package is supported or patched. Check the vendor notice and package changelog for the exact package and release you run.
- Identify the container runtime and its source: for example, a distribution package, a Docker-managed component, or another vendor build.
- Look up the relevant CVE in that vendor’s security notice and confirm the fixed package version for your operating-system release.
- Install the supported update using the vendor’s normal package-management process, then verify the installed package against the notice or changelog.
- For Buildx users, review whether builds run concurrently with custom shared mounts, the condition described for CVE-2025-52881.
What reduces risk while you update?
Mitigations reduce exposure or limit damage; they are not substitutes for installing the supported fix. Their value depends on the vulnerability and how containers are configured, and the CVE-2025-52565 advisory warns that protections may be less effective when flaws are chained.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
- Use user namespaces with host root unmapped. This reduces the host privileges available to a process running as root inside a container.
- Consider rootless containers. Rootless operation can further reduce the privileges available to a compromised runtime process.
- For containers that are not user-namespaced, use a non-root container user and
noNewPrivilegeswhere suitable. These settings can restrict what a compromised process can do, but do not repair the runtime flaw. - Avoid untrusted images. This is particularly relevant where the attack path requires a malicious image; still, it does not cover every race or configuration-based path.
How severe are these vulnerabilities?
The CVSS values are severity scores for particular vulnerabilities and attack variants, not estimates of how many Docker hosts are exposed or compromised. OpenContainers/runc assigned CVSS 3.1 scores of 8.2 and 8.6 to variants of CVE-2024-21626. Its advisories score the described primary attacks for CVE-2025-31133 and CVE-2025-52565 at 7.3 using CVSS v4; the CVE-2025-31133 masked-path bypass variant is 5.6 under CVSS v4. These scores should not be combined into one risk score for Docker as a whole.
The cited advisories do not establish an exploitation rate, a count of affected Docker hosts, or an incident total. A severity score alone is not evidence that a flaw is being widely exploited.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
Can a Docker container escape to the host?
Yes, some of these CVEs describe conditional paths to host files, sensitive host operations, or a container breakout. Whether a particular host is affected depends on the CVE, runtime package, and attack prerequisites. CVE-2026-41579 is a notable exception for Docker: its upstream advisory says Docker’s masking prevents exploitation of that specific issue.
What should Docker operators take away?
Treat “runC flaws” as a group of separate vulnerabilities, not one generic exploit. Match each CVE to its stated conditions, use the vendor’s package advisory to establish patch status, and reduce container privileges while updates are applied. The advisories support serious, configuration-dependent risks; they do not support claiming that every Docker container is exploitable or that all hosts face the same exposure.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

