CVE-2024-21626PoC(fedoraproject / fedora)

HIGHCVSS 8.6 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fedoraproject fedora systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-403CWE-668CWE-200

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fedora
  • runc

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Peaked 1d ago at 2 mentions (2026-07-10); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Products
fedorarunc

1 version affected across 2 products

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-02-28: 1Mentions · 2026-03-15: 1Mentions · 2026-03-16: 1Mentions · 2026-06-26: 1Mentions · 2026-07-10: 2Mentions · 2026-08-31: 1PoC Mentioned / Linked · 2026-03-15: 1PoC Mentioned / Linked · 2026-03-16: 1PoC Mentioned / Linked · 2026-08-31: 1Active Exploitation · 2026-07-10: 2Patch / Workaround · 2026-06-26: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-16: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-10: 2Technical Details · 2026-08-31: 102-2803-1503-1606-2607-1008-31
Signal classification4 categories
PoC
342.9%
Active Exploitation
228.6%
Exploit
114.3%
Patch
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-281
Exploit1
2026-03-151
PoC1
2026-03-161
PoC1
2026-06-261
Patch1
2026-07-102
Active Exploitation2
2026-08-311
PoC1
Full discourse7 posts
  • Clandestine@akaclandestine
    PoC

    CVE-2024-21626: runc Container Breakout Vulnerability | Bug-Bounty notes https://cipherops.gitbook.io/bug-bounty-notes/cve-2024-21626-runc-container-breakout-vulnerability

    Post summary

    The post references CVE-2024-21626 and links to bug‑bounty notes that likely contain a proof of concept, but it does not highlight any exploit code, patch, or evidence of active exploitation.

    0301131.6K
    56.1K followersView on X
  • felipehuici@felipehuici
    Active Exploitation

    If you're running critical or multi-tenant workloads on containers, you're playing with fire. The CVE record keeps proving it: - CVE-2024-21626 — Leaky Vessels: runc container escape, host filesystem access - CVE-2025-23266 — NVIDIAScape: CVSS 9.0, triggered by a 3-line Dockerfile - CVE-2025-52881 — runc procfs write-redirect: full breakout, actively exploited in the wild by mid-2026 - CVE-2025-38617 — Linux kernel packet-socket: full container escape via user namespaces This is not a 2024 phenomenon that someone will eventually fix. The November-2025 runc trio (CVE-2025-31133 / -52565 / -52881) moved from disclosure to confirmed in-the-wild exploitation, affecting Docker, containerd and every major managed Kubernetes service. Escapes never stopped — 2024-2025 brought a fresh surge, and by 2026 the worst of them are being exploited for real. Containers don't contain. ⚠️ 📄 Full blog post: https://unikraft.com/blog/the-mighty-microvm

    Post summary

    The post highlights that multiple runc and kernel CVEs are actively exploited in the wild, underscoring persistent container escape threats.

    00066569
    909 followersView on X
  • shubham kumar@kumar98_shubham
    PoC

    Proof, not theory. Jan 2024, CVE-2024-21626: runc leaked a file descriptor. The container reached the host filesystem. Mount namespace was intact. Escape was an fd runc forgot to close. 2025: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881. Mount races. Write to protected host paths from inside the container.

    Post summary

    The post presents a proof of concept demonstrating a privileged escape in runc via an unclosed file descriptor and highlights additional mount race vulnerabilities in 2025, but does not provide exploit code, patches, or evidence of active exploitation.

    1000027
    45 followersView on X
  • Jérôme Jaggi@JeromeJaggi
    Active Exploitation

    Can someone explain to me why people still trust containers? - CVE-2024-21626 (Leaky Vessels) - CVE-2025-23266 (NVIDIAScape, CVSS 9.0, a 3-line Dockerfile) - CVE-2025-52881 (runc procfs write-redirect, actively exploited in the wild by mid-2026). Those are some prominent examples but there are lots more and they are recurring, publicly disclosed vulnerabilities affecting Docker, containerd, and every major managed Kubernetes service. Also, the trend from 2024 to 2026 is not improving 😅 Containers are great for packaging and distribution - but the problem is still that a shared-kernel container was never architected to be a hard, multi-tenant security boundary, and the CVE record keeps proving it. Long live the microVM 🎉 🔗 Read the full blog post here: https://unikraft.com/blog/the-mighty-microvm

    Post summary

    The post highlights several container-related CVEs, noting that at least one (CVE-2025-52881) has been exploited in the wild, underscoring ongoing security concerns with container platforms.

    0001040
    15 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2024-21626 (CVSS 8.6) - runc container escape vulnerability in versions ≤1.1.11. Attackers can access host filesystem & overwrite binaries. Update to 1.1.12 immediately. #CVE #Vulnerability #PatchNow https://t.co/DlPne9ygkN

    Post summary

    The tweet announces CVE-2024-21626, a high-severity container escape flaw in runc, and urges users to update to version 1.1.12 immediately.

    0000032
    52 followersView on X
  • Milos Constantin ♏(@Tinolle hachyderm.io )@Tinolle
    PoC

    https://cipherops.gitbook.io/bug-bounty-notes/cve-2024-21626-runc-container-breakout-vulnerability

    Post summary

    A link to a note on CVE-2024-21626 implies that a proof‑of‑concept for this runc container breakout exists and technical details are provided, but there is no evidence of active exploitation, patches, or debunking.

    00000101
    3.2K followersView on X
  • strikoder@Strikoder
    Exploit

    New HackTheBox walkthrough: Giveback WordPress RCE → Kubernetes pivoting with Ligolo-ng → PHP-CGI exploitation → runc CVE-2024-21626 container escape to root. Advanced cloud-native pentesting chain. https://youtu.be/du1cABpynLI #HackTheBox #Kubernetes #ContainerEscape

    Post summary

    The post outlines a HackTheBox walkthrough that demonstrates a multi-stage exploitation chain ending with a container escape via CVE-2024-21626, but it does not provide code or evidence of active attacks.

    0000096
    15 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora39--
Applinuxfoundationrunc---

Explore more