CVE-2015-3629: Docker Libcontainer

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.

Affected products

  • Docker Libcontainer: version 1.6.0 only
  • Opensuse Opensuse: version 13.2 only

Published 2015-05-18. Last modified 2026-06-17.