High severity8.5NVD Advisory· Published May 27, 2021· Updated Jun 17, 2026
CVE-2021-30465
CVE-2021-30465
Description
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/opencontainers/runcGo | < 1.0.0-rc95 | 1.0.0-rc95 |
Affected products
105- osv-coords86 versionspkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/runc&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/opensuse/docker&distro=openSUSE%20Leap%2015.2pkg:golang/github.com/opencontainers/runcpkg:rpm/opensuse/docker&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/runc&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/runc&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/docker&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/runc&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/docker&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Micro%205.0pkg:apk/chainguard/runc-docpkg:apk/wolfi/runc-docpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP3pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/containerd&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/docker&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/containerd&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/runc&distro=SUSE%20Manager%20Server%204.0pkg:apk/chainguard/runcpkg:apk/wolfi/runcpkg:rpm/almalinux/containers-commonpkg:rpm/almalinux/critpkg:rpm/almalinux/criupkg:rpm/almalinux/fuse-overlayfspkg:rpm/almalinux/python-podman-apipkg:rpm/almalinux/python3-criupkg:rpm/almalinux/skopeopkg:rpm/almalinux/skopeo-testspkg:rpm/almalinux/slirp4netnspkg:rpm/almalinux/toolboxpkg:rpm/almalinux/udicapkg:rpm/almalinux/libslirppkg:rpm/almalinux/libslirp-develpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Micro%205.0pkg:rpm/suse/docker&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/runc&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweedpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/almalinux/cockpit-podmanpkg:rpm/almalinux/conmonpkg:rpm/almalinux/container-selinuxpkg:rpm/almalinux/containernetworking-pluginspkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP3pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP2pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Micro%205.0pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP2pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP2pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP3pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/containerd&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/containerd&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/opensuse/runc&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/containerd&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/opensuse/runc&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/containerd&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/docker-kubic&distro=openSUSE%20Leap%2015.3
< 20.10.6_ce-6.49.3+ 85 more
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 20.10.6_ce-lp152.2.12.1
- (no CPE)range: < 1.0.0-rc95
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 1:0.1.41-4.module_el8.5.0+108+00865455
- (no CPE)range: < 3.12-9.module_el8.3.0+2044+12421f43
- (no CPE)range: < 3.12-9.module_el8.4.0+2496+12421f43
- (no CPE)range: < 0.7.8-1.module_el8.5.0+108+00865455
- (no CPE)range: < 1.2.0-0.2.gitd0a45fe.module_el8.5.0+2635+e4386a39
- (no CPE)range: < 3.12-9.module_el8.3.0+2044+12421f43
- (no CPE)range: < 1:0.1.41-4.module_el8.5.0+2635+e4386a39
- (no CPE)range: < 1:0.1.41-4.module_el8.5.0+108+00865455
- (no CPE)range: < 0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39
- (no CPE)range: < 0.0.7-1.module_el8.5.0+108+00865455
- (no CPE)range: < 0.2.1-2.module_el8.5.0+108+00865455
- (no CPE)range: < 4.3.1-1.module_el8.6.0+2876+9ed4eae2
- (no CPE)range: < 4.3.1-1.module_el8.6.0+2876+9ed4eae2
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.4.11-16.45.1
- (no CPE)range: < 0.0.20250807T150727-1.1
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 11-1.module_el8.5.0+108+00865455
- (no CPE)range: < 2:2.0.15-1.module_el8.5.0+108+00865455
- (no CPE)range: < 2:2.130.0-1.module_el8.5.0+2635+e4386a39
- (no CPE)range: < 0.8.3-4.module_el8.5.0+2635+e4386a39
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.0.0~rc93-16.11.1
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 20.10.9_ce-98.72.1
- (no CPE)range: < 1.4.11-56.1
- (no CPE)range: < 20.10.9_ce-156.1
- (no CPE)range: < 1.0.2-23.1
- (no CPE)range: < 1.0.2-1.2
- (no CPE)range: < 1.4.4-lp152.2.6.1
- (no CPE)range: < 20.10.6_ce-6.49.3
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 1.0.0~rc93-1.14.2
- (no CPE)range: < 1.0.0~rc93-lp152.2.3.1
- (no CPE)range: < 1.4.4-5.32.1
- (no CPE)range: < 20.10.9_ce-156.1
- runc/runcdescription
cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*range: <=0.1.1
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc10:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc5:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc6:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc7:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc8:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc9:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc90:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc91:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc92:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc93:*:*:*:*:*:*
- cpe:2.3:a:linuxfoundation:runc:1.0.0:rc94:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
15- github.com/opencontainers/runc/commit/0ca91f44f1664da834bc61115a849b56d22f595fnvdPatchThird Party AdvisoryWEB
- github.com/opencontainers/runc/security/advisories/GHSA-c3xm-pvg7-gh7rnvdPatchThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2021/05/19/2nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-c3xm-pvg7-gh7rghsaADVISORY
- github.com/opencontainers/runc/releasesnvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-30465ghsaADVISORY
- security.gentoo.org/glsa/202107-26nvdThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20210708-0003/nvdThird Party Advisory
- bugzilla.opensuse.org/show_bug.cginvdIssue TrackingWEB
- lists.debian.org/debian-lts-announce/2023/03/msg00023.htmlnvdWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/35ZW6NBZSBH5PWIT7JU4HXOXGFVDCOHHghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/4HOARVIT47RULTTFWAU7XBG4WY6TDDHVghsaWEB
- security.netapp.com/advisory/ntap-20210708-0003ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/35ZW6NBZSBH5PWIT7JU4HXOXGFVDCOHH/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4HOARVIT47RULTTFWAU7XBG4WY6TDDHV/nvd
News mentions
0No linked articles in our index yet.