Alpine: multiple runc packages: security update to 1.4.3-r0

low Tenable Cloud Security Plugin ID 443383

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- runc is a CLI tool for spawning and running containers according to the OCI specification. In versions
prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs,
setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string which allow an
image with /dev as a symlink to trick runc into deleting files called ptmx on the host or creating a
hardcoded set of symlinks with specific names and targets in an arbitrary pre-existing host directory.
This issue is not exploitable under Docker, because Docker creates a top-level read-only layer that masks
any malicious /dev symlink present in the container image — unlike some other Linux container tooling,
whose higher-level runtimes built on runc remain exposed to exploitation via a malicious image. This issue
has been fixed in versions 1.3.6, 1.4.3 and 1.5.0. (CVE-2026-41579)

Solution

Update the runc library and its related packages to version 1.4.3-r0 or later.

See Also

https://security.alpinelinux.org/vuln/CVE-2026-41579

Plugin Details

Severity: Low

ID: 443383

Version: Revision 1.2

Type: Local

Published: 6/18/2026

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.2

Percentile: 51.07

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-41579

CVSS v3

Risk Factor: Low

Base Score: 3.3

Temporal Score: 2.9

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Reference Information

CVE: CVE-2026-41579