AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2019-19921.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 08, 2026

Disclosure summary

### Impact By crafting a malicious root filesystem (with `/proc` being a symlink to a directory which was inside a volume shared with another running container), an attacker in control of both containers can trick `runc` into not correctly configuring the container's security labels and not correctly masking paths inside `/proc` which contain potentially-sensitive information about the host (or even allow for direct attacks against the host). In order to exploit this bug, an untrusted user must be able to spawn custom containers with custom mount configurations (such that a volume is shared between two containers). It should be noted that we consider this to be a fairly high level of access for an untrusted user -- and we do not recommend allowing completely untrusted users to have such degrees of access without further restrictions. ### Specific Go Package Affected github.com/opencontainers/runc/libcontainer ### Patches This vulnerability has been fixed in `1.0.0-rc10`. It should be noted that the current fix is effectively a hot-fix, and there are known ways for it to be worked around (such as making the entire root filesystem a shared volume controlled by another container). We

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-fh74-hm69-rqjw

Open original source · Updated Oct 08, 2026

opencontainers runc contains procfs race condition with a shared volume mount

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/opencontainers/runc< 1.0.0-rc9.0.20200122160610-2fc03cc11c771.0.0-rc9.0.20200122160610-2fc03cc11c77

Original records & references

PUBLISHED 2021-05-27T14:41:17-04:00
MODIFIED 2026-10-08T07:04:27-04:00
INGESTED 2026-10-08T12:30:44-04:00