CVE-2019-5736General(apache / backports_sle)

CRITICALCVSS 8.6 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch apache backports_sle systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • backports_sle
  • container_development_kit
  • dc\/os
  • docker

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-10); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
backports_slecontainer_development_kitdc\/osdockerenterprise_linuxenterprise_linux_serverfedorahci_management_nodekubernetes_engineleap

21 versions affected across 18 products

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-26: 1Mentions · 2026-04-30: 1Mentions · 2026-05-10: 3Mentions · 2026-09-03: 1PoC Mentioned / Linked · 2026-02-26: 1Exploit Tool / Code · 2026-02-26: 1Active Exploitation · 2026-02-26: 1Patch / Workaround · 2026-05-10: 1Technical Details · 2026-02-26: 1Technical Details · 2026-05-10: 2Technical Details · 2026-09-03: 102-2604-3005-1009-03
Signal classification3 categories
General
466.7%
Exploit
116.7%
Patch
116.7%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-261
Exploit1
2026-04-301
General1
2026-05-103
General2Patch1
2026-09-031
General1
Full discourse6 posts
  • swing@bestswngs
    General

    CVE-2026-31431 让我想起22年研究DirtyPipe 的时候,当时容器相关的exploit 方法印象中是两个 1. overlap 去横向打cross container 2. 通过 CVE-2019-5736 的思路去修改 runc https://t.co/b2sOhFTFCf

    Post summary

    The tweet mentions CVE‑2026‑31431 in the context of container exploits, referencing past DirtyPipe research and CVE‑2019‑5736, but it provides no concrete evidence of exploitation, patches, or technical vulnerability details.

    15089378.9K
    3.4K followersView on X
  • ngCERT@ngCERTofficial
    General

    🚨CRITICAL Docker, Kubernates and containerd users are all at risk. A flaw in runc (CVE-2019-5736) lets attackers break out of containers and take over the host without special privileges. Find out more on our website https://cert.gov.ng/advisories/critical-runc-container-escape-vulnerability #Cybersecurity #advisory https://t.co/zZzvKfZdYt

    Post summary

    The tweet warns that runc CVE‑2019‑5736 can cause container escape and host takeover for Docker, Kubernetes, and containerd users, with a link for more details.

    05041228
    1.4K followersView on X
  • Grok@grok
    Exploit

    A solid example of Docker isolation failing: CVE-2019-5736 in runc (Docker's default runtime). If the AI agent (running as root, common in sandboxes) drops malicious code that overwrites the host's runc binary via a /proc/self/exe symlink trick during any exec, boom—next 'docker exec' or attach runs the payload on the *host* as root. No mounts or rm -rf needed; pure runtime exploit. Real PoCs from 2019 let attackers fully own the machine. AI code gen could trigger this unintentionally.

    Post summary

    The post highlights a real-world exploit of CVE-2019-5736 in Docker’s runc, detailing how a symlink trick can overwrite the host binary and achieve root execution, with PoCs from 2019 confirming its effectiveness.

    12030284
    8.3M followersView on X
  • Aleksa Sarai 暗号君@lordcyphar
    Patch

    @andersonc0d3 @dinodaizovi Yes, it's /proc/self/exe. It boils down to doing CVE-2019-5736 but via page-cache poisoning. My initial patch for that would create a copy of the binary in a sealed memfd for every container run (meaning a unique instance in the page cache) but we had to switch to something else.

    Post summary

    The comment discusses a mitigative patch for CVE‑2019‑5736 focused on page‑cache poisoning, but does not mention a PoC, exploit tool, or active exploitation.

    1002070
    1.2K followersView on X
  • Aleksa Sarai 暗号君@lordcyphar
    General

    @markasoftware_ @D1iv3 There isn't really a way around it, to create a container process you need to join while still executing container runtime code. As I mentioned in another thread, my first version of the protection against CVE-2019-5736 actually protected against page-cache poisoning attacks...

    Post summary

    The message references defensive measures against CVE-2019-5736 and notes page-cache poisoning as a concern, but offers no PoC, exploit, patch details, or evidence of active exploitation.

    1001037
    1.2K followersView on X
  • Aleksa Sarai 暗号君@lordcyphar
    General

    @markasoftware_ @D1iv3 This is basically just a page cache poisoning variant of CVE-2019-5736.

    Post summary

    The tweet simply notes the existence of a page cache poisoning variant of CVE-2019-5736, offering no further detail or actionable information.

    1000065
    1.2K followersView on X
CPE platform detail38 entries

38 of 38 entries

PartVendorProductVersionTarget SWTarget HW
Appapachemesos---
OScanonicalubuntu_linux16.04--
OScanonicalubuntu_linux18.04--
OScanonicalubuntu_linux18.10--
OScanonicalubuntu_linux19.04--
OSd2iqdc\/os---
Appd2iqkubernetes_engine---
Appdockerdocker---
OSfedoraprojectfedora29--
OSfedoraprojectfedora30--
Appgooglekubernetes_engine---
Apphponesphere---
Applinuxcontainerslxc---
Applinuxfoundationrunc---
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Appmicrofocusservice_management_automation2018.02--
Appmicrofocusservice_management_automation2018.05--
Appmicrofocusservice_management_automation2018.08--
Appmicrofocusservice_management_automation2018.11--
Appnetapphci_management_node---
Appnetappsolidfire---
Appopensusebackports_sle15.0--
Appopensusebackports_sle15.0--
OSopensuseleap15.0--
OSopensuseleap15.1--
OSopensuseleap42.3--
Appredhatcontainer_development_kit3.7--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux_server7.0--
Appredhatopenshift3.4--
Appredhatopenshift3.5--
Appredhatopenshift3.6--
Appredhatopenshift3.7--

Explore more