Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-5736

91
FAUCET Score

CVE-2019-5736 is a critical vulnerability in runc, affecting Docker before 18.09.2 and other containerization products. It allows an attacker to overwrite the host runc binary, leading to host root access, by exploiting file-descriptor mishandling related to /proc/self/exe within a container. With a CVSS score of 8.6 (HIGH), this vulnerability has a low attack complexity and can result in complete compromise of confidentiality, integrity, and availability of the host system. While not on the KEV catalog, exploit modules are publicly available in Metasploit and ExploitDB, and it has garnered significant community discussion and media coverage, indicating high awareness and potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 18.09.2CPE matchmatch criteria
cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*
<= 0.1.1CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:1.0.0:rc1:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:1.0.0:rc2:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:1.0.0:rc3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.6HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
98.07%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Metasploit: Docker Container Escape Via runC Overwrite · Jan 1, 2019
ExploitDB: EDB-46369 · Feb 13, 2019
This CVE's current EPSS score of 0.9807 is in the 100th percentile among its peer group of 11,615 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 16833-16820Fixed in: -
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 0.4.1+azure-3
microsoftpatch availablevia msrc
Product: cm1 moby-buildx 0.4.1+azure-3 on CBL Mariner 1.0Fixed in: -
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 0.4.1+azure-3
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:rhel8-8000020190416221845.2ffa3d27
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.4Fixed in: docker-2:1.12.6-79.git5680db5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.5Fixed in: docker-2:1.12.6-79.git5680db5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.6Fixed in: docker-2:1.12.6-79.git5680db5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.7Fixed in: docker-2:1.12.6-79.git5680db5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 ExtrasFixed in: runc-0:1.0.0-59.dev.git2abd837.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 ExtrasFixed in: docker-2:1.13.1-91.git07f3374.el7
View patch
redhatpatch availablevia redhat_api
Product: Other
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: docker-latest
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.9Fixed in: runc

Vendor Advisories (3)

microsoft2021-Jul/CVE-2019-5736

CVE-2019-5736

Jul 13, 2021
microsoft2019-Feb/CVE-2019-5736Important

runc through 1.0-rc6 as used in Docker before 18.09.2 and other products allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image or (2) an existing container to which the attacker previously had write access that can be attached with docker exec. This occurs because of file-descriptor mishandling related to /proc/self/exe.

Feb 12, 2019
redhatCVE-2019-5736Important

runc: Execution of malicious containers allows for container escape and access to host filesystem

Feb 11, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-03/msg00044.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-04/msg00074.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-04/msg00091.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-05/msg00060.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-05/msg00073.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-06/msg00011.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-06/msg00015.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-08/msg00084.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-10/msg00007.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-10/msg00029.html
Mailing ListThird Party Advisory
packetstormsecurity.com / files/163339/Docker-Container-Escape.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/165197/Docker-runc-Command-Execution-Proof-Of-Concept.html
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2019:0303
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0304
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0401
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0408
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0975
Third Party Advisory
access.redhat.com / security/cve/cve-2019-5736
Third Party Advisory
access.redhat.com / security/vulnerabilities/runcescape
Third Party Advisory
aws.amazon.com / security/security-bulletins/AWS-2019-002
Third Party Advisory
azure.microsoft.com / en-us/updates/cve-2019-5736-and-runc-vulnerability
PatchThird Party AdvisoryVendor Advisory
azure.microsoft.com / en-us/updates/iot-edge-fix-cve-2019-5736
PatchThird Party AdvisoryVendor Advisory
blog.dragonsector.pl / 2019/02/cve-2019-5736-escape-from-docker-and.html
ExploitMitigationThird Party Advisory
brauner.github.io / 2019/02/12/privileged-containers.html
ExploitTechnical DescriptionThird Party Advisory
bugzilla.suse.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
cloud.google.com / kubernetes-engine/docs/security-bulletins
Third Party Advisory
github.com / docker/docker-ce/releases/tag/v18.09.2
Release NotesThird Party Advisory
github.com / Frichetten/CVE-2019-5736-PoC
ExploitThird Party Advisory
github.com / opencontainers/runc/commit/0a8e4117e7f715d5fbeef398405813ce8e88558b
PatchThird Party Advisory
github.com / opencontainers/runc/commit/6635b4f0c6af3810594d2770f662f34ddc15b40d
PatchThird Party Advisory
github.com / q3k/cve-2019-5736-poc
ExploitThird Party Advisory
github.com / rancher/runc-cve
Third Party Advisory
kubernetes.io / blog/2019/02/11/runc-and-cve-2019-5736
Third Party Advisory
lists.apache.org / thread.html/24e54e3c6b2259e3903b6b8fe26896ac649c481ea99c5739468c92a3%40%3Cdev.dlab.apache.org%3E
lists.apache.org / thread.html/a258757af84c5074dc7bf932622020fd4f60cef65a84290380386706%40%3Cuser.mesos.apache.org%3E
lists.apache.org / thread.html/a585f64d14c31ab393b90c5f17e41d9765a1a17eec63856ce750af46%40%3Cdev.dlab.apache.org%3E
lists.apache.org / thread.html/acacf018c12636e41667e94ac0a1e9244e887eef2debdd474640aa6e%40%3Cdev.dlab.apache.org%3E
lists.apache.org / thread.html/b162dd624dc088cd634292f0402282a1d1d0ce853baeae8205bc033c%40%3Cdev.mesos.apache.org%3E
lists.apache.org / thread.html/rc494623986d76593873ce5a40dd69cb3629400d10750d5d7e96b8587%40%3Cdev.dlab.apache.org%3E
lists.apache.org / thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/DLC52IOJN6IQJWJ6CUI6AIUP6GVVG2QP
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/EGZKRCKI3Y7FMADO2MENMT4TU24QGHFR
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/SWFJGIPYAAAMVSWWI3QWYXGA3ZBU2H4W
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/V6A4OSFM5GGOWW4ECELV5OHX2XRAUSPH
security.gentoo.org / glsa/202003-21
Third Party Advisory
security.netapp.com / advisory/ntap-20190307-0008
Third Party Advisory
softwaresupport.softwaregrp.com / document/-/facetsearch/document/KM03410944
Third Party Advisory
support.hpe.com / hpsc/doc/public/display
Permissions Required
support.mesosphere.com / s/article/Known-Issue-Container-Runtime-Vulnerability-MSPH-2019-0003
ExploitPatchThird Party Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20190215-runc
Third Party Advisory
usn.ubuntu.com / 4048-1
Third Party Advisory
exploit-db.com / exploits/46359
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/46369
ExploitThird Party AdvisoryVDB Entry
openwall.com / lists/oss-security/2019/02/11/2
Mailing ListPatchThird Party Advisory
synology.com / security/advisory/Synology_SA_19_06
Third Party Advisory
twistlock.com / 2019/02/11/how-to-mitigate-cve-2019-5736-in-runc-and-docker
Third Party Advisory
openwall.com / lists/oss-security/2019/03/23/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/06/28/2
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/07/06/3
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/07/06/4
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/10/24/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/10/29/3
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2024/01/31/6
openwall.com / lists/oss-security/2024/02/01/1
openwall.com / lists/oss-security/2024/02/02/3
securityfocus.com / bid/106976
Third Party AdvisoryVDB Entry