VDB

RHSA-2026%3A6492

RHSA-2026%3A6492 PUBLISHED CVSS 8.199999809265137 HIGH

A flaw was found in runc. This flaw exploits an issue with how masked paths are implementedin runc. When masking files, runc will bind-mount the container's /dev/null inode on top of the file. However, if an attacker can replace /dev/null with a symlink to some other procfs file, runc will instead bind-mount the symlink target read-write.

Risk Scores

CVSS 3.1
8.199999809265137
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatrhcos-x86_64-412.86.202604010116-0 as a component of Red Hat OpenShift Container Platform 4.12rhcos-x86_64-412.86.202604010116-0, 412.86.202604010116-0

Timeline

  • Apr 9, 2026 CVE Published
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 14, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›