Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-21626-runcPOC — Proof-of-concept for CVE-2024-21626, a runc container escape vulnerability. Includes verification scripts, two exploitation methods (cron reverse shell and command replacement), and analysis of the root cause and patch. | Kitploit
Tools/GitHubGitHub/v0wkeep3r/cve-2024-21626-runcpoc
Privilege EscalationContainer SecurityVulnerability AnalysisExploitationCloud SecurityContainer Escape
GitHubv0wkeep3r/cve-2024-21626-runcpoc

CVE-2024-21626-runcPOC

Proof-of-concept for CVE-2024-21626, a runc container escape vulnerability. Includes verification scripts, two exploitation methods (cron reverse shell and command replacement), and analysis of the root cause and patch.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
61172 years agoNot yet reviewed

[Vulnerability Reproduction] CVE-2024-21626 docker runc Escape Vulnerability

1. Vulnerability Overview

Vulnerability Namedocker runc Escape Vulnerability
CVE IDCVE-2024-21626
Disclosure Date2024-01-31
Characteristic/
Affected Versionsrunc @ [v1.0.0-rc93, 1.1.11]

2. Exploitation & POC/EXP

Exploitation Conditions are somewhat strict, requiring victim interaction. Personally, I find it a bit lackluster:

  1. Use the attacker's malicious image (including settings like the working directory) to create a container
  2. The attacker can control the container and execute commands.

Verify Vulnerability and Obtain File Descriptor:

git clone https://github.com/V0WKeep3r/CVE-2024-21626-runcPOC.git
cd CVE-2024-21626-runcPOC
bash verify.sh

As shown below, the vulnerability exists, and the file descriptor is /proc/self/fd8 verify.sh can find the specific fd value corresponding to the current machine environment. If the fd is not 8, you need to modify the WORKDIR in the Dockerfile to the corresponding value or use -w in docker run to specify it.

Escape/Privilege Escalation Verification: I designed this to be more practical. poc.sh uses a cron job to spawn a reverse shell. poc2.sh uses command replacement (note: using this method requires backing up files in advance to avoid difficulty in recovery).

# 需要确认定时任务文件存在,不存在可以创建写,但是那样不能触发定时任务
# 只有crontab -e创建的,在crontab组的文件才会被定时执行。
docker build . -t poc1
docker run -it --rm poc1 bash /poc.sh

POC2:

docker build . -t poc2
docker run -it --rm poc2 bash /poc.sh

# 另起一个terminal
/bin/bash.copy

3. Vulnerability Principle Analysis

Not fully understood, but with the patch, we can get a general idea.

During the process of docker exec or docker run, runc's execve function is called. However, during runc exec, the file descriptor (fd) is not closed, causing the host's file descriptors to be leaked into the container environment. Users can use this file descriptor to read and write host files, thereby achieving container escape.

4. Fix Solution / Patch Analysis

Fix Solution Upgrade runc to version 1.12 or above. Official runc link: https://github.com/opencontainers/runc/releases

Patch Analysis Diff commit: https://github.com/opencontainers/runc/commit/2a4ed3e75b9e80d93d1836a9c4c1ebfa2b78870e Close internal fds in time before execve. In init_linux.go, after chdir, verify that cwd (current working directory) is inside the container.

F. References

  1. Vulnerability Description: https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv
  2. Patch: https://github.com/opencontainers/runc/commit/2a4ed3e75b9e80d93d1836a9c4c1ebfa2b78870e
Download Tool