UNIX Symbolic Link (Symlink) Following Affecting github.com/opencontainers/runc/libcontainer package, versions <1.3.6>=1.4.0-rc.1 <1.4.3>=1.5.0-rc.1 <1.5.0-rc.3


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.19% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMOPENCONTAINERSRUNCLIBCONTAINER-17337039
  • published14 Jun 2026
  • disclosed13 Jun 2026
  • creditDavias,Arthur Chan,JUNYI LIU,Derek Manzella

Introduced: 13 Jun 2026

CVE-2026-41579  (opens in a new tab)
CWE-61  (opens in a new tab)

How to fix?

Upgrade github.com/opencontainers/runc/libcontainer to version 1.3.6, 1.4.3, 1.5.0-rc.3 or higher.

Overview

github.com/opencontainers/runc/libcontainer is a package for a modern container runtime.

Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following in setupPtmx and setupDevSymlinks, which enable file deletion via calls to os.Remove and os.Symlink. An attacker who supplies a container image whose /dev is a symlink can redirect these operations outside the container, deleting host files named ptmx or creating a fixed set of named symlinks: core, fd, ptmx, stdin, stdout, stderr, in an arbitrary preexisting host directory. The practical impact is limited, since the symlink names and targets are fixed and unlikely to point to attacker-controlled data, and the ptmx files although guaranteed to exist, cannot be removed due to devpts constraints.

Note: This vulnerability is not exploitable under Docker.

CVSS Base Scores

version 4.0
version 3.1