CVE-2026-41579: Verified Reproduction
CVE-2026-41579: runc symlink deletion via malicious /dev symlink in container image
CVE-2026-41579 is verified against the affected target. This low reproduction includes runnable sandbox proof, artifacts, and a plain-text agent view under REPRO-2026-00206.
What Is CVE-2026-41579?
CVE-2026-41579 is a low-severity symlink-following issue (CWE-61) in opencontainers/runc where a malicious container image can trick runc into deleting a host file and creating symlinks on the host during rootfs setup. Pruva reproduced it (reproduction REPRO-2026-00206).
CVE-2026-41579 Severity & CVSS Score
CVE-2026-41579 is rated low severity, with a CVSS base score of 3.3 out of 10.
Low — limited impact or hard to exploit. Address in the normal cycle.
How to Reproduce CVE-2026-41579
pruva-verify REPRO-2026-00206 curl -O https://www.pruva.dev/api/v1/reproductions/REPRO-2026-00206/artifacts/bundle/repro/reproduction_steps.sh && chmod +x reproduction_steps.sh && ./reproduction_steps.sh Proof of Reproduction for CVE-2026-41579
- reached the target end-to-end
- on the real production code path
- high confidence
- the upstream fix blocks the same trigger
container image rootfs where /dev is a symlink to an attacker-controlled host directory
- runc run cve-ptmx-test -b /bundle
- rootfs /dev setup
- setupPtmx/setupDevSymlinks
How the agent worked
Root Cause and Exploit Chain for CVE-2026-41579
CVE-2026-41579 is a low-severity host filesystem integrity issue in opencontainers/runc. When runc prepares a container rootfs, the functions setupPtmx and setupDevSymlinks operate on path strings under the bundle rootfs before pivot_root(2) occurs. If the container image has /dev as a symlink that points outside the rootfs (for example to a host directory controlled by the attacker), filepath.Join(rootfs, "/dev/ptmx") resolves through the symlink and runc deletes or re-creates files on the host. A malicious image can therefore trick runc into removing an existing file named ptmx and creating a small fixed set of device symlinks in an attacker-chosen host directory.
- Package / component: opencontainers/runc
- Affected versions: prior to 1.3.6, 1.4.0-rc.1 through 1.4.3, and 1.5.0-rc.1 through 1.5.0-rc.3
- Risk level: low (per upstream advisory)
- Consequences: Arbitrary deletion of a host file named
ptmxand creation of a limited set of hardcoded symlinks in a host directory reachable via a malicious/devsymlink. Not exploitable under Docker, but exploitable via other runc-based runtimes that do not mask/devwith a top-level read-only layer.
Impact Parity
- Disclosed / claimed maximum impact: Arbitrary file deletion and symlink creation on the host filesystem through a malicious container image (
/devsymlink). - Reproduced impact from this run: Vulnerable runc deleted a decoy file named
ptmxand replaced it with a symlink in an attacker-controlled directory; fixed runc left the decoy untouched. - Parity:
fullfor the documented filesystem-integrity impact. The reproduction does not demonstrate privilege escalation or code execution, which is consistent with the advisory's low-severity rating.
Root Cause
The bug is in runc's rootfs preparation code. Before the container pivots into its rootfs, setupPtmx and setupDevSymlinks use filepath.Join(rootfs, "/dev/...") and then call os.Remove / os.Symlink. Because the operations happen before pivot_root, a /dev entry in the image that is a symlink to an attacker-controlled host directory is followed, causing the operations to affect the host path instead of the container rootfs.
Upstream fix commit:
opencontainers/runc@864db8042dbb— "rootfs: make /dev initialisation code fd-based"
The fix rewrites the /dev setup code to operate on file descriptors relative to the opened rootfs directory, so symlinks in the image cannot redirect the operations to host paths.
Reproduction Steps
The reproduction is implemented in bundle/repro/reproduction_steps.sh. At a high level it:
- Verifies Docker is available.
- Downloads the vulnerable runc release binary (
v1.3.5) and the fixed release binary (v1.3.6). - Builds a minimal OCI rootfs from the official
busyboximage. - Builds two privileged Docker images (
repro-runc-vulnandrepro-runc-fixed) that each contain one runc binary and the rootfs. - Inside a privileged container, replaces
/bundle/rootfs/devwith a symlink to/controlled_devand creates a decoy/controlled_dev/ptmx. - Generates an OCI bundle with
runc spec, disables the terminal, and sets the command to/bin/true. - Runs
runc run cve-ptmx-test -b /bundle. - Checks whether the decoy file was deleted.
Expected evidence:
- Vulnerable (1.3.5): the
ptmxdecoy is removed and/controlled_devcontains symlinks such asptmx -> pts/ptmx,core -> /proc/kcore,fd -> /proc/self/fd, etc. - Fixed (1.3.6): the
ptmxdecoy remains untouched and runc does not create host symlinks.
Evidence
bundle/logs/repro_vuln.log— vulnerable runc 1.3.5 deletes the decoy and creates host symlinks.bundle/logs/repro_fixed.log— fixed runc 1.3.6 preserves the decoy.bundle/logs/build_repro-runc-vuln.log— Docker build log for the vulnerable image.bundle/logs/build_repro-runc-fixed.log— Docker build log for the fixed image.bundle/repro/runtime_manifest.json— runtime evidence manifest produced by the script.
Key excerpts:
Vulnerable run:
RUN_VERSION: runc version 1.3.5
BEFORE: /controlled_dev/ptmx present?
-rw-r---- 1 root root 10 ... ptmx
...
AFTER: /controlled_dev contents:
-rw-r--r-- ... ptmx
RESULT: decoy deleted
Fixed run:
RUN_VERSION: runc version 1.3.6
BEFORE: /controlled_dev/ptmx present?
-rw-r--r-- ... ptmx
...
AFTER: /controlled_dev contents:
-rw-r--r-- ... ptmx
RESULT: decoy preserved
Recommendations / Next Steps
- Upgrade runc to a patched version: 1.3.6, 1.4.3, or 1.5.0 (or later).
- Higher-level runtimes that consume runc should ensure container images cannot ship a
/devsymlink that resolves to a host path, or rely on the patched runc version. - Regression tests should include a rootfs where
/devis a symlink to a controlled host directory and verify thatsetupPtmx/setupDevSymlinksdo not operate on the host path.
Additional Notes
- The script is idempotent: it re-downloads only missing binaries, rebuilds the Docker images each run, and uses unique container names.
- The reproduction uses the real
runcCLI binary and the real OCI bundle execution path (runc run), not a reimplemented parser or mocked environment. - The Docker-in-Docker privileged container is required in this sandbox because the host environment lacks
CAP_SYS_ADMINand a writable cgroup hierarchy; inside the privileged container runc has the capabilities needed to create a genuine container. - No sanitizer or crash is involved; the proof relies on the filesystem state difference between the vulnerable and fixed versions.
CVE-2026-41579 Reproduction Transcript
The agent's step-by-step process — every tool call, every handoff, the moment the exploit fired.
Full session Replay every step — scrub the timeline or play it back.
Artifacts and Evidence for CVE-2026-41579
Scripts, logs, diffs, and output captured during the reproduction.
How to Fix CVE-2026-41579
FAQ: CVE-2026-41579
How does the CVE-2026-41579 symlink attack work?
/dev symlinked to an attacker-chosen host directory causes runc to delete an existing file named ptmx on the host and create a small, fixed set of device symlinks in that attacker-controlled directory. This is not exploitable under Docker, but affects other container tooling built on runc that does not mask /dev with a top-level read-only layer.Which runc versions are affected by CVE-2026-41579, and where is it fixed?
How severe is CVE-2026-41579?
How can I reproduce CVE-2026-41579?
References for CVE-2026-41579
Authoritative sources for CVE-2026-41579 — official vulnerability databases and the upstream advisory. Pruva's reproduction verifies the issue firsthand; these are the primary records to corroborate it.