CVE-2019-16884: High severity linuxfoundation Runc vulnerability
Last updated 25 August 2025
Other sources
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfslinux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-16884.
What is the severity rating of CVE-2019-16884?
The severity rating of CVE-2019-16884 is medium, with a severity value of 6.5.
What is the affected software for CVE-2019-16884?
The affected software for CVE-2019-16884 includes runc versions 1.0.0-rc8 and earlier, used in Docker versions through 19.03.2-ce.
How does CVE-2019-16884 allow AppArmor restriction bypass?
CVE-2019-16884 allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, allowing a malicious Docker image to mount over a /proc directory.
Are there any references available for CVE-2019-16884?
Yes, there are references available for CVE-2019-16884: [Reference 1](https://github.com/opencontainers/runc/issues/2128), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DGK6IV5JGVDXHOXEKJOJWKOVNZLT6MYR/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/62OQ2P7K5YDZ5BRCH2Q6DHUJIHQD3QCD/)