Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-45310

16
FAUCET Score

CVE-2024-45310 is a low-severity vulnerability in runc, a container runtime, affecting versions 1.1.13 and earlier, and 1.2.0-rc2 and earlier, including its use in Docker and Kubernetes. It allows an attacker with the ability to configure custom volumes to create empty files or directories in arbitrary host filesystem locations by exploiting a race condition during volume sharing. The attack requires user interaction (UI:R) and has a low impact, primarily affecting integrity (I:L) by creating empty files without truncating existing ones. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.1.14CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*
1.2.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:1.2.0:rc1:*:*:*:*:*:*
1.2.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:1.2.0:rc2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.6LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 39th percentile among its peer group of 577 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (20)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/opencontainers/runcFixed in: 1.1.14
gopatch availablevia ghsa
Product: github.com/opencontainers/runcFixed in: 1.2.0-rc.3
microsoftpatch availablevia msrc
Product: cbl2 moby-runc 1.1.9-8 on CBL Mariner 2.0Fixed in: 1.1.9-8
microsoftpatch availablevia msrc
Product: 17640-17084Fixed in: 1.2.2-1
microsoftpatch availablevia msrc
Product: 19725-17084Fixed in: 1.2.2-1
microsoftpatch availablevia msrc
Product: 17802-17084Fixed in: 1.32.0-1
microsoftpatch availablevia msrc
Product: 19772-17086Fixed in: 1.1.9-8
microsoftpatch availablevia msrc
Product: azl3 runc 1.2.2-1 on Azure Linux 3.0Fixed in: 1.2.2-1
microsoftpatch availablevia msrc
Product: azl3 runc 1.1.12-2 on Azure Linux 3.0Fixed in: 1.2.2-1
microsoftpatch availablevia msrc
Product: azl3 cri-tools 1.30.1-1 on Azure Linux 3.0Fixed in: 1.32.0-1
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: runc
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:rhel8/runc
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: runc
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: runc
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 6Fixed in: grafana
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 7Fixed in: grafana
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 8Fixed in: grafana
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 9Fixed in: grafana

Vendor Advisories (3)

microsoft2024-Sep/CVE-2024-45310Low

runc can be confused to create empty files/directories on the host

Sep 10, 2024
goGHSA-jfvp-7x6p-h2pvmedium

runc can be confused to create empty files/directories on the host

Sep 3, 2024
redhatCVE-2024-45310Low

runc: runc can be tricked into creating empty files/directories on host

Sep 3, 2024

References

security.netapp.com / advisory/ntap-20250221-0008
Vendor Advisory
openwall.com / lists/oss-security/2024/09/03/1
Mailing ListMitigationThird Party Advisory
github.com / opencontainers/runc/commit/63c2908164f3a1daea455bf5bcd8d363d70328c7
Patch
github.com / opencontainers/runc/commit/8781993968fd964ac723ff5f360b6f259e809a3e
Patch
github.com / opencontainers/runc/commit/f0b652ea61ff6750a8fcc69865d45a7abf37accf
Patch
github.com / opencontainers/runc/pull/4359
Patch
github.com / opencontainers/runc/security/advisories/GHSA-jfvp-7x6p-h2pv
PatchVendor Advisory