CVE & CISA-KEV Catalog

CVE-2024-21626

HIGHEPSS 97th pctl
8.6
CVSS v3
NVD

Description

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

How to fix

Remediation Available
runcDebian
Fixed in:1.0.0~rc93+ds1-5+deb11u3CVE-2024-21626
Fixed in:1.1.5+ds1-1+deb12u1CVE-2024-21626
Fixed in:1.1.12+ds1-1CVE-2024-21626
Fixed in:1.1.12+ds1-1CVE-2024-21626
aardvark-dns-2:1.0.1Rocky
Fixed in:28.module+el8.6.0+21254+7ef668f8.s390x::container-tools:4.0RHSA-2024:0757
Fixed in:40.module+el8.6.0+21266+3e24c7b3.ppc64le::container-tools:rhel8RHSA-2024:0764
Fixed in:38.module+el8.9.0+21242+944321bb.ppc64le::container-tools:4.0RHSA-2024:0748
Fixed in:38.module+el8.9.0+21242+944321bb.x86_64::container-tools:4.0RHSA-2024:0748
Fixed in:28.module+el8.6.0+21254+7ef668f8.ppc64le::container-tools:4.0RHSA-2024:0757
Fixed in:40.module+el8.6.0+21266+3e24c7b3.s390x::container-tools:rhel8RHSA-2024:0764
Fixed in:28.module+el8.6.0+21254+7ef668f8.aarch64::container-tools:4.0RHSA-2024:0757
Fixed in:40.module+el8.6.0+21266+3e24c7b3.x86_64::container-tools:rhel8RHSA-2024:0764
aardvark-dns-2:1.0.1Red Hat / RHEL
Fixed in:38.module+el8.9.0+21242+944321bb.ppc64le::container-tools:4.0RHSA-2024:0748
Fixed in:38.module+el8.9.0+21242+944321bb.x86_64::container-tools:4.0RHSA-2024:0748
Fixed in:40.module+el8.6.0+21266+3e24c7b3.s390x::container-tools:rhel8RHSA-2024:0764
Fixed in:38.module+el8.9.0+21242+944321bb.aarch64::container-tools:4.0RHSA-2024:0748
Fixed in:28.module+el8.6.0+21254+7ef668f8.s390x::container-tools:4.0RHSA-2024:0757
Fixed in:40.module+el8.6.0+21266+3e24c7b3.ppc64le::container-tools:rhel8RHSA-2024:0764
Fixed in:40.module+el8.6.0+21266+3e24c7b3.aarch64::container-tools:rhel8RHSA-2024:0764
Fixed in:40.module+el8.6.0+21266+3e24c7b3.x86_64::container-tools:rhel8RHSA-2024:0764
aardvark-dns-2:1.5.0Red Hat / RHEL
Fixed in:2.module+el8.8.0+21265+93802b02.ppc64le::container-tools:rhel8RHSA-2024:0759
Fixed in:2.module+el8.8.0+21265+93802b02.aarch64::container-tools:rhel8RHSA-2024:0759
Fixed in:2.module+el8.8.0+21265+93802b02.s390x::container-tools:rhel8RHSA-2024:0759
Fixed in:2.module+el8.8.0+21265+93802b02.src::container-tools:rhel8RHSA-2024:0759
Fixed in:2.module+el8.8.0+21265+93802b02.x86_64::container-tools:rhel8RHSA-2024:0759
aardvark-dns-2:1.5.0Rocky
Fixed in:2.module+el8.8.0+21265+93802b02.ppc64le::container-tools:rhel8RHSA-2024:0759
Fixed in:2.module+el8.8.0+21265+93802b02.x86_64::container-tools:rhel8RHSA-2024:0759
Fixed in:2.module+el8.8.0+21265+93802b02.src::container-tools:rhel8RHSA-2024:0759
Fixed in:2.module+el8.8.0+21265+93802b02.aarch64::container-tools:rhel8RHSA-2024:0759
Fixed in:2.module+el8.8.0+21265+93802b02.s390x::container-tools:rhel8RHSA-2024:0759
aardvark-dns-2:1.7.0Rocky
Fixed in:1.module+el8.9.0+21243+a586538b.aarch64::container-tools:rhel8RHSA-2024:0752
Fixed in:1.module+el8.9.0+21243+a586538b.ppc64le::container-tools:rhel8RHSA-2024:0752
Fixed in:1.module+el8.9.0+21243+a586538b.x86_64::container-tools:rhel8RHSA-2024:0752
Fixed in:1.module+el8.9.0+21243+a586538b.src::container-tools:rhel8RHSA-2024:0752
Fixed in:1.module+el8.9.0+21243+a586538b.s390x::container-tools:rhel8RHSA-2024:0752
aardvark-dns-2:1.7.0Red Hat / RHEL
Fixed in:1.module+el8.9.0+21243+a586538b.x86_64::container-tools:rhel8RHSA-2024:0752
Fixed in:1.module+el8.9.0+21243+a586538b.ppc64le::container-tools:rhel8RHSA-2024:0752
Fixed in:1.module+el8.9.0+21243+a586538b.s390x::container-tools:rhel8RHSA-2024:0752
Fixed in:1.module+el8.9.0+21243+a586538b.src::container-tools:rhel8RHSA-2024:0752
Fixed in:1.module+el8.9.0+21243+a586538b.aarch64::container-tools:rhel8RHSA-2024:0752
bpftoolRed Hat / RHEL
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
bpftoolRocky
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
bpftool-debuginfoRocky
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
bpftool-debuginfoRed Hat / RHEL
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
Fixed in:0:4.18.0-372.89.1.el8_6RHSA-2024:0666
Fixed in:0:4.18.0-372.91.1.el8_6RHSA-2024:0684
buildah-0:1.11.6Red Hat / RHEL
Fixed in:8.module+el8.2.0+21264+96602818.ppc64le::container-tools:2.0RHSA-2024:0758
Fixed in:8.module+el8.2.0+21264+96602818.src::container-tools:2.0RHSA-2024:0758
Fixed in:8.module+el8.2.0+21264+96602818.x86_64::container-tools:2.0RHSA-2024:0758
buildah-0:1.11.6Rocky
Fixed in:8.module+el8.2.0+21264+96602818.ppc64le::container-tools:2.0RHSA-2024:0758
Fixed in:8.module+el8.2.0+21264+96602818.src::container-tools:2.0RHSA-2024:0758
Fixed in:8.module+el8.2.0+21264+96602818.x86_64::container-tools:2.0RHSA-2024:0758
buildah-0:1.19.9Red Hat / RHEL
Fixed in:1.module+el8.4.0+21078+a96cfbf6.x86_64::container-tools:3.0RHSA-2024:0760
Fixed in:1.module+el8.4.0+21078+a96cfbf6.ppc64le::container-tools:3.0RHSA-2024:0760
Fixed in:1.module+el8.4.0+21078+a96cfbf6.src::container-tools:3.0RHSA-2024:0760
buildah-0:1.19.9Rocky
Fixed in:1.module+el8.4.0+21078+a96cfbf6.x86_64::container-tools:3.0RHSA-2024:0760
Fixed in:1.module+el8.4.0+21078+a96cfbf6.ppc64le::container-tools:3.0RHSA-2024:0760
Fixed in:1.module+el8.4.0+21078+a96cfbf6.src::container-tools:3.0RHSA-2024:0760
buildah-1:1.24.2Red Hat / RHEL
Fixed in:3.module+el8.6.0+21254+7ef668f8.src::container-tools:4.0RHSA-2024:0757
Fixed in:3.module+el8.6.0+21254+7ef668f8.aarch64::container-tools:4.0RHSA-2024:0757
Fixed in:3.module+el8.6.0+21254+7ef668f8.s390x::container-tools:4.0RHSA-2024:0757
Fixed in:3.module+el8.6.0+21254+7ef668f8.x86_64::container-tools:4.0RHSA-2024:0757
Fixed in:3.module+el8.6.0+21254+7ef668f8.ppc64le::container-tools:4.0RHSA-2024:0757
buildah-1:1.24.2Rocky
Fixed in:3.module+el8.6.0+21254+7ef668f8.ppc64le::container-tools:4.0RHSA-2024:0757
Fixed in:3.module+el8.6.0+21254+7ef668f8.s390x::container-tools:4.0RHSA-2024:0757
Fixed in:3.module+el8.6.0+21254+7ef668f8.aarch64::container-tools:4.0RHSA-2024:0757
Fixed in:3.module+el8.6.0+21254+7ef668f8.src::container-tools:4.0RHSA-2024:0757
Fixed in:3.module+el8.6.0+21254+7ef668f8.x86_64::container-tools:4.0RHSA-2024:0757
buildah-1:1.24.6Red Hat / RHEL
Fixed in:7.module+el8.9.0+21242+944321bb.src::container-tools:4.0RHSA-2024:0748
Fixed in:7.module+el8.9.0+21242+944321bb.ppc64le::container-tools:4.0RHSA-2024:0748
Fixed in:7.module+el8.9.0+21242+944321bb.s390x::container-tools:4.0RHSA-2024:0748
Fixed in:7.module+el8.9.0+21242+944321bb.aarch64::container-tools:4.0RHSA-2024:0748
Fixed in:7.module+el8.9.0+21242+944321bb.x86_64::container-tools:4.0RHSA-2024:0748
buildah-1:1.24.6Rocky
Fixed in:7.module+el8.9.0+21242+944321bb.src::container-tools:4.0RHSA-2024:0748
Fixed in:7.module+el8.9.0+21242+944321bb.ppc64le::container-tools:4.0RHSA-2024:0748
Fixed in:7.module+el8.9.0+21242+944321bb.s390x::container-tools:4.0RHSA-2024:0748
Fixed in:7.module+el8.9.0+21242+944321bb.aarch64::container-tools:4.0RHSA-2024:0748
Fixed in:7.module+el8.9.0+21242+944321bb.x86_64::container-tools:4.0RHSA-2024:0748
buildah-1:1.26.2Red Hat / RHEL
Fixed in:1.module+el8.6.0+21266+3e24c7b3.aarch64::container-tools:rhel8RHSA-2024:0764
Fixed in:1.module+el8.6.0+21266+3e24c7b3.src::container-tools:rhel8RHSA-2024:0764
Fixed in:1.module+el8.6.0+21266+3e24c7b3.x86_64::container-tools:rhel8RHSA-2024:0764
Fixed in:1.module+el8.6.0+21266+3e24c7b3.s390x::container-tools:rhel8RHSA-2024:0764
Fixed in:1.module+el8.6.0+21266+3e24c7b3.ppc64le::container-tools:rhel8RHSA-2024:0764
buildah-1:1.26.2Rocky
Fixed in:1.module+el8.6.0+21266+3e24c7b3.x86_64::container-tools:rhel8RHSA-2024:0764
Fixed in:1.module+el8.6.0+21266+3e24c7b3.src::container-tools:rhel8RHSA-2024:0764
Fixed in:1.module+el8.6.0+21266+3e24c7b3.ppc64le::container-tools:rhel8RHSA-2024:0764
Fixed in:1.module+el8.6.0+21266+3e24c7b3.aarch64::container-tools:rhel8RHSA-2024:0764
Fixed in:1.module+el8.6.0+21266+3e24c7b3.s390x::container-tools:rhel8RHSA-2024:0764
buildah-1:1.29.2Rocky
Fixed in:1.module+el8.8.0+21265+93802b02.x86_64::container-tools:rhel8RHSA-2024:0759
Fixed in:1.module+el8.8.0+21265+93802b02.ppc64le::container-tools:rhel8RHSA-2024:0759
Fixed in:1.module+el8.8.0+21265+93802b02.src::container-tools:rhel8RHSA-2024:0759
Fixed in:1.module+el8.8.0+21265+93802b02.aarch64::container-tools:rhel8RHSA-2024:0759
Fixed in:1.module+el8.8.0+21265+93802b02.s390x::container-tools:rhel8RHSA-2024:0759
buildah-1:1.29.2Red Hat / RHEL
Fixed in:1.module+el8.8.0+21265+93802b02.x86_64::container-tools:rhel8RHSA-2024:0759
Fixed in:1.module+el8.8.0+21265+93802b02.ppc64le::container-tools:rhel8RHSA-2024:0759
Fixed in:1.module+el8.8.0+21265+93802b02.s390x::container-tools:rhel8RHSA-2024:0759
Fixed in:1.module+el8.8.0+21265+93802b02.aarch64::container-tools:rhel8RHSA-2024:0759
Fixed in:1.module+el8.8.0+21265+93802b02.src::container-tools:rhel8RHSA-2024:0759
buildah-1:1.31.3Red Hat / RHEL
Fixed in:3.module+el8.9.0+21243+a586538b.x86_64::container-tools:rhel8RHSA-2024:0752
Fixed in:3.module+el8.9.0+21243+a586538b.aarch64::container-tools:rhel8RHSA-2024:0752
Fixed in:3.module+el8.9.0+21243+a586538b.ppc64le::container-tools:rhel8RHSA-2024:0752
Fixed in:3.module+el8.9.0+21243+a586538b.s390x::container-tools:rhel8RHSA-2024:0752
Fixed in:3.module+el8.9.0+21243+a586538b.src::container-tools:rhel8RHSA-2024:0752
buildah-1:1.31.3Rocky
Fixed in:3.module+el8.9.0+21243+a586538b.ppc64le::container-tools:rhel8RHSA-2024:0752
Fixed in:3.module+el8.9.0+21243+a586538b.s390x::container-tools:rhel8RHSA-2024:0752
Fixed in:3.module+el8.9.0+21243+a586538b.aarch64::container-tools:rhel8RHSA-2024:0752
Fixed in:3.module+el8.9.0+21243+a586538b.src::container-tools:rhel8RHSA-2024:0752
Fixed in:3.module+el8.9.0+21243+a586538b.x86_64::container-tools:rhel8RHSA-2024:0752
buildah-debuginfo-0:1.11.6Red Hat / RHEL
Fixed in:8.module+el8.2.0+21264+96602818.x86_64::container-tools:2.0RHSA-2024:0758
Fixed in:8.module+el8.2.0+21264+96602818.ppc64le::container-tools:2.0RHSA-2024:0758
buildah-debuginfo-0:1.11.6Rocky
Fixed in:8.module+el8.2.0+21264+96602818.x86_64::container-tools:2.0RHSA-2024:0758
Fixed in:8.module+el8.2.0+21264+96602818.ppc64le::container-tools:2.0RHSA-2024:0758
buildah-debuginfo-0:1.19.9Rocky
Fixed in:1.module+el8.4.0+21078+a96cfbf6.ppc64le::container-tools:3.0RHSA-2024:0760
Fixed in:1.module+el8.4.0+21078+a96cfbf6.x86_64::container-tools:3.0RHSA-2024:0760
buildah-debuginfo-0:1.19.9Red Hat / RHEL
Fixed in:1.module+el8.4.0+21078+a96cfbf6.x86_64::container-tools:3.0RHSA-2024:0760
Fixed in:1.module+el8.4.0+21078+a96cfbf6.ppc64le::container-tools:3.0RHSA-2024:0760
buildah-debuginfo-1:1.24.2Red Hat / RHEL
Fixed in:3.module+el8.6.0+21254+7ef668f8.s390x::container-tools:4.0RHSA-2024:0757
Fixed in:3.module+el8.6.0+21254+7ef668f8.x86_64::container-tools:4.0RHSA-2024:0757
Fixed in:3.module+el8.6.0+21254+7ef668f8.aarch64::container-tools:4.0RHSA-2024:0757
Fixed in:3.module+el8.6.0+21254+7ef668f8.ppc64le::container-tools:4.0RHSA-2024:0757

This vulnerability affects an unusually large number of packages. The highest-confidence fixes are shown above; the full list is longer. Check the referenced advisories for complete coverage.

TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeChanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Exploit Intelligence

18.09%probability of exploitation in 30 days
97thpercentile

Very high risk: more likely to be exploited than 97% of all known CVEs.

References

Related Vulnerabilities

Other CWE-403 vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2024-58280High8.80.9%--
CVE-2025-15114Critical9.80.6%--
CVE-2026-16526High8.80.5%-Fix
CVE-2026-12296Critical9.60.4%-Fix
CVE-2025-3032High7.40.4%-Fix
CVE-2026-40042Critical9.80.4%--

Common questions

How do I fix CVE-2024-21626?

Published advisories record a fix for 521 affected products. The "How to fix" section on this page lists the fixed version and source advisory for each one, so apply the entry matching what you actually run.

Is CVE-2024-21626 being actively exploited?

Not that we know of. CVE-2024-21626 is not in the CISA Known Exploited Vulnerabilities catalog. Its EPSS score of 18.1% is the estimated probability that it will be exploited in the next 30 days. That is higher than 97% of all scored CVEs.

How severe is CVE-2024-21626?

CVE-2024-21626 has a CVSS v3 base score of 8.6, rated high. CVSS rates the technical impact if the vulnerability is exploited, not how likely that is, so weigh it alongside the exploit-prediction score when you decide what to patch first.

What does CVE-2024-21626 affect?

Published advisories record a fix for runc (Debian), aardvark-dns-2:1.0.1 (Rocky), aardvark-dns-2:1.0.1 (Red Hat / RHEL), aardvark-dns-2:1.5.0 (Red Hat / RHEL), and 517 more. The list on this page is capped, so there may be more.

Embed a live status badge for CVE-2024-21626
CVE-2024-21626 severity badge

Markdown

[![CVE-2024-21626](https://tridentstack.com/cve/badge/CVE-2024-21626.svg)](https://tridentstack.com/cve/CVE-2024-21626)

HTML

<a href="https://tridentstack.com/cve/CVE-2024-21626"><img src="https://tridentstack.com/cve/badge/CVE-2024-21626.svg" alt="CVE-2024-21626"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

See how it worksStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-08-24.