Vulnerability record · CVE-2019-5736 · published 11 February 2019
CVE-2019-5736: runc container escape via /proc/self/exe overwrite of host binary
Docker · Docker
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, mishandles file descriptors related to /proc/self/exe, letting an attacker overwrite the host runc binary from inside a container. Because runc runs as root on the host, this yields host root access and breaks the container isolation boundary.
Description
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.6 with scope change to host root and very high EPSS, but exploitation requires local access and user interaction and it is not in CISA KEV.
What it is
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, mishandles file descriptors related to /proc/self/exe, letting an attacker overwrite the host runc binary from inside a container. Because runc runs as root on the host, this yields host root access and breaks the container isolation boundary.
Impact
An attacker who can execute a command as root inside a targeted container gains root on the host by replacing the runc binary. This is a full container escape with high confidentiality, integrity and availability impact on the host.
Attack surface
Reached locally from within a container: either a new container started from an attacker-controlled image, or an existing container the attacker previously had write access to and can attach to with docker exec. The CVSS vector shows local access, no privileges, and required user interaction (UI:R), with scope change to the host.
Exploitation
Public exploit code is referenced (Packet Storm Docker container escape and runc command execution PoC), and EPSS is very high at 0.98452 (99.9th percentile), though CISA KEV does not list it.
What to do
- Patch runc to a fixed release and upgrade Docker to 18.09.2 or later; apply vendor errata for affected distributions and products.
- Do not run containers from untrusted or attacker-controlled images, and restrict who can write to container filesystems or use docker exec.
- Where patching is not immediate, apply vendor or upstream hardening guidance for runc/Docker to reduce the attack path.
- Limit container root privileges and avoid granting untrusted workloads the ability to execute commands as root inside containers.
Detection
- Monitor for unexpected modification or replacement of the host runc binary (hash and file integrity monitoring).
- Alert on container processes accessing /proc/self/exe in ways consistent with the exploit, and on suspicious docker exec activity into containers.
- Audit container image provenance and flag containers started from unknown or attacker-controlled images.
- Watch for privilege escalation from container context to host root, including new root processes on the host tied to container activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-5736 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-5736), CISA KEV, FIRST EPSS (scores of 2026-09-17). This page is refreshed as NVD updates the record.