GO-2022-0274: Namespace restriction bypass in github.com/opencontainers/runc
GO-2022-0452: Default inheritable capabilities for linux container should be empty in github.com/opencontainers/runc
GO-2023-1627: Opencontainers runc Incorrect Authorization vulnerability in github.com/opencontainers/runc
GO-2023-1682: Rootless: /sys/fs/cgroup is writable when cgroupns isn't unshared in github.com/opencontainers/runc
GO-2023-1683: AppArmor bypass with symlinked /proc in github.com/opencontainers/runc
GO-2024-2491: Container breakout through process.cwd trickery and leaked fds in github.com/opencontainers/runc
GO-2024-3110: Can be confused to create empty files/directories on the host in github.com/opencontainers/runc
GO-2025-3543: WITHDRAWN: Libcontainer is affected by capabilities elevation in github.com/opencontainers/runc
GO-2025-4096: Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc
GO-2025-4097: Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc
GO-2025-4098: Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc