HOMEVULNERABILITIESCVE-2019-5736
HIGHPOC

CVE-2019-5736

CWE-78Published: February 11, 2019· Updated: Jun 17, 2026

8.6
CVSS v3.1

Official Description

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

NVD Source

Technical Analysis

CVE-2019-5736 requires local access, meaning attackers must already have a foothold on the target system.

Exploitation does not require any privileges, though user interaction (Required) is needed, which slightly reduces the risk of mass automated attacks.

A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 8.6.

The vulnerability has a "Changed" scope, meaning successful exploitation can impact components beyond the vulnerable component itself — such as the host operating system or adjacent services.

A proof-of-concept (PoC) exploit exists for CVE-2019-5736. While not yet confirmed in active campaigns, the availability of PoC code increases exploitation risk substantially.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorLocal
Attack ComplexityLow
Privileges Req.None
User InteractionRequired
ScopeChanged
Impact
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Vendors & Products

Apache1 product(s)
mesos
Canonical1 product(s)
ubuntu linux
d2iq2 product(s)
kubernetes enginedc\/os
Docker1 product(s)
docker
Fedora1 product(s)
fedora
Google1 product(s)
kubernetes engine
HP1 product(s)
onesphere
linuxcontainers1 product(s)
lxc
linuxfoundation1 product(s)
runc
microfocus1 product(s)
service management automation
netapp2 product(s)
hci management nodesolidfire
openSUSE2 product(s)
backports sleleap
Red Hat4 product(s)
container development kitopenshiftenterprise linuxenterprise linux server
Source: NVD CPE · 32 total CPE entries

Exploit & PoC Resources

POC AVAILABLEProof-of-concept code exists
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (132)

Quick Facts

CVE IDCVE-2019-5736
CVSS Score8.6 / 10
SeverityHIGH
WeaknessCWE-78
CISA KEVNo
ExploitPOC
Affected13 vendor(s)
PublishedFeb 11, 2019

Related CVEs (CWE-78)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2019-5736 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.