Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

OpenShift and other Docker-based systems on Red Hat vulnerable to privilege escalation

RHSA-2026:3291
Summary

A security update is available for runc, a component used by OpenShift and other Docker-based systems on Red Hat. This update fixes a vulnerability that could allow an attacker to gain elevated privileges on a system. To stay secure, Red Hat users should apply this update as soon as possible.

What to do
  • Update redhat runc to version 4:1.4.0-2.el9_7.
  • Update redhat runc-debuginfo to version 4:1.4.0-2.el9_7.
  • Update redhat runc-debugsource to version 4:1.4.0-2.el9_7.
Affected software
VendorProductAffected versionsFix available
redhat runc <= 4:1.4.0-2.el9_7 4:1.4.0-2.el9_7
redhat runc-debuginfo <= 4:1.4.0-2.el9_7 4:1.4.0-2.el9_7
redhat runc-debugsource <= 4:1.4.0-2.el9_7 4:1.4.0-2.el9_7
Original title
Red Hat Security Advisory: runc security update
osv CVSS3.1 7.5
Published: 26 Feb 2026 · Updated: 7 Mar 2026 · First seen: 6 Mar 2026