Sploitus

CVE-2024-21626

35 known exploits for CVE-2024-21626

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

Linuxfoundation Runc
< 1.1.12
Fix
Available
CVSS 3.1
8.6 HIGH
EPSS
18.1% (97th percentile)
Weakness
CWE-403, CWE-668, CWE-200
NVD status
Modified
Published
2024-01-31
CVE-2024-21626 at NVD
Authoritative description, scoring and affected products

35 known exploits for CVE-2024-21626

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2024-21626
2026-08-28 KitPloitKITPLOIT
CVE-2024-21626
2026-08-27 KitPloitKITPLOIT
pisc
2026-08-27 KitPloitKITPLOIT
CVE-2024-21626-PoC
2026-08-27 KitPloitKITPLOIT
CVE-2024-21626-old-docker-versions
2026-08-27 KitPloitKITPLOIT
container-escape-ebpf
2026-08-27 KitPloitKITPLOIT
CVE-2024-21626
2026-08-27 KitPloitKITPLOIT
CVE-2024-21626
2026-08-27 KitPloitKITPLOIT
CVE-2024-21626-runcPOC
2026-08-27 KitPloitKITPLOIT
CVE-2024-21262
2026-08-27 KitPloitKITPLOIT
cve-2024-21626
2026-08-27 KitPloitKITPLOIT
CVE-2024-21626
2026-08-27 KitPloitKITPLOIT
CVE-2024-21626-POC
2026-08-26 KitPloitKITPLOIT
cve-2024-21626-runc-1.1.11-escape
2026-08-26 KitPloitKITPLOIT
CVE-2024-21626
2026-08-26 KitPloitKITPLOIT
CVE-2024-21626-demo
2026-08-26 KitPloitKITPLOIT
CVE-2024-21626
2026-08-26 KitPloitKITPLOIT
CVE-2024-21626-POC
2026-08-26 KitPloitKITPLOIT
Exploit for Exposure of Resource to Wrong Sphere in Linuxfoundation Containerd
2026-03-29 nouhailaw77-gifGITHUB
Exploit for Exposure of Resource to Wrong Sphere in Linuxfoundation Containerd
2026-03-29 0x3lr3yyyGITHUB
Exploit for OS Command Injection in Docker
2026-02-14 AI-redteamGITHUB
Exploit for Incorrect Authorization in Oracle Mysql
2025-10-10 Noah4PuppyGITHUB
Exploit for File Descriptor Leak in Linuxfoundation Runc
2025-08-02 R4mbbGITHUB
Exploit for File Descriptor Leak in Linuxfoundation Runc
2025-08-02 R4mbbGITHUB
Exploit for File Descriptor Leak in Linuxfoundation Runc
2024-08-25 FlojBojGITHUB
Exploit for File Descriptor Leak in Linuxfoundation Runc
2024-04-03 KubernetesBachelorGITHUB
Exploit for File Descriptor Leak in Linuxfoundation Runc
2024-03-15 Sk3pperGITHUB
runc 1.1.11 File Descriptor Leak Privilege Escalation
2024-02-05 h00die, Rory McNamara, metasploit.comPACKETSTORMRuby
runc 1.1.11 File Descriptor Leak Privilege Escalation Exploit
2024-02-05 metasploitZDTRuby
Exploit for File Descriptor Leak in Linuxfoundation Runc
2024-02-05 V0WKeep3rGITHUB
Exploit for File Descriptor Leak in Linuxfoundation Runc
2024-02-02 Wall1eGITHUB
Exploit for File Descriptor Leak in Linuxfoundation Runc
2024-02-02 cdxiaodongGITHUB
Exploit for File Descriptor Leak in Linuxfoundation Runc
2024-02-01 NitroCaoGITHUB
Exploit for File Descriptor Leak in Linuxfoundation Runc
2024-02-01 zpxlzGITHUB
runc (docker) File Descriptor Leak Privilege Escalation
2024-01-31 h00die, SickMcNugget, jheysel-r7, Rory McNamaraMETASPLOITRuby