Your message dated Thu, 06 Aug 2026 11:49:14 +0000
with message-id <[email protected]>
and subject line Bug#1140000: fixed in runc 1.3.6+ds1-1
has caused the Debian Bug report #1140000,
regarding runc: CVE-2026-41579
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1140000: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140000
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: runc
Version: 1.3.5+ds1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for runc.
CVE-2026-41579[0]:
| runc allows a malicious image with a /dev symlink to trigger limited
| host filesystem integrity violations
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-41579
https://www.cve.org/CVERecord?id=CVE-2026-41579
[1] https://www.openwall.com/lists/oss-security/2026/06/13/2
[2]
https://github.com/opencontainers/runc/security/advisories/GHSA-xjvp-4fhw-gc47
[3]
https://github.com/opencontainers/runc/commit/864db8042dbb191028676f80addf8c35f348aee2
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: runc
Source-Version: 1.3.6+ds1-1
Done: Reinhard Tartler <[email protected]>
We believe that the bug you reported is fixed in the latest version of
runc, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Reinhard Tartler <[email protected]> (supplier of updated runc package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 06 Aug 2026 13:33:30 +0200
Source: runc
Architecture: source
Version: 1.3.6+ds1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <[email protected]>
Changed-By: Reinhard Tartler <[email protected]>
Closes: 1046528 1140000
Changes:
runc (1.3.6+ds1-1) unstable; urgency=medium
.
* New upstream release
* Fixes CVE-2026-41579: a malicious image with a /dev symlink could
cause limited host filesystem integrity violations (Closes: #1140000)
* Fix a regression in v1.3.0 that could result in a stuck `runc exec`
or `runc run` when the container process runs for a short time
* Reuse a single read-only tmpfs when masking directories, reducing
tmpfs superblock churn (relevant for Kubernetes per-CPU sysfs masks)
* debian/clean: clean up generated man pages so that the source
package can be built again after a successful build (Closes: #1046528)
* Bump Standards Version, drop Priority: optional
Checksums-Sha1:
0d5cbc201532789dff8cf7cbdcc3f15cfa61e5c5 3464 runc_1.3.6+ds1-1.dsc
1235fa0071e850008f616e726e790cf946f88831 521740 runc_1.3.6+ds1.orig.tar.xz
da436d31ece9d9eaf4ded131c73af32d863baa3a 13596 runc_1.3.6+ds1-1.debian.tar.xz
Checksums-Sha256:
a7eff082067a6914a2b6f8bdc53a9d13dc29a092804750214dceaddbc35b6769 3464
runc_1.3.6+ds1-1.dsc
008c1386c4e36cedf0f4a8c1e74da3d0dfc6789f73e166b8b8df5f107ac5edb8 521740
runc_1.3.6+ds1.orig.tar.xz
22aaf23f2b2cd43f7107d77352ebabf1b11d2cc602ca19964f408b2b72a1b1ff 13596
runc_1.3.6+ds1-1.debian.tar.xz
Files:
241ad55055e0f9f707720b876e474572 3464 admin optional runc_1.3.6+ds1-1.dsc
971970016cd35763fa2374f65a4de61c 521740 admin optional
runc_1.3.6+ds1.orig.tar.xz
d32b82fe9521121624ac47f4b4afa8a2 13596 admin optional
runc_1.3.6+ds1-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCgAyFiEEMN59F2OrlFLH4IJQSadpd5QoJssFAmp0cZwUHHNpcmV0YXJ0
QHRhdXdhcmUuZGUACgkQSadpd5QoJsslZA/+MUowzpgf51NuiYYAJv0oJVWiIhgZ
U8Z+R0XhfqCDsNekW58dmPkrEkktQYZa5CgQlVYglVBrjSoWWM7tHFWHz9Me7eh+
mObETnTlNxyxQ6gBejc69LKPUE4lFedLDK1BaTvNegPUvXvmZO7fdWBAZn4Aaqsf
Eetd8hf3xHmoUbWH7WuPGCfiptXb3s6kuxmQkBcrXKvvkT8rcZnFdcoPPdAC2an4
tw42bRA9MTZAnahG1C5nfzYu90bOIgNKVldQ2f1j5+vhsQVH93bB/GhPkkgp631b
hs3oERPJWDT34OUT8V6I2wjrktLSRa73w0//p7vdX1oft93Ce2vh2z4xntc+DgoP
56RPydvzbgtGEXuKBR5xnm2oL3kUtVTBeQU1yBQgKKFP+t8CERY+Q4p0wKVDbkSz
IT04aPA+P3qM8UDao3LNhhMBKIPVOiKsI4XQgPsbOu2JlT2mZuRok4HtvQvxOtdR
Yj+zdtIBvTU6rRjeY5fnfhV4W5Yf8IJvNzurSSVrVYEHqF8b7Jr0tdz+pd8ogkKU
u+OzHKJLplcBIJHH0VA46yMcmBhSnWZhKXYSvkwtNgPsoQx8CEzWWhuWZ/5LM9Cr
7Bm2CdjDLDjpG9eWSG4MwQg6EECdx2t0vr5wEC04fd6RABwA9tYM9Fu84NwqV1ce
+TL7OdAz8z1Fwac=
=Lm/m
-----END PGP SIGNATURE-----
pgpUKLmI3CnMz.pgp
Description: PGP signature
--- End Message ---