Skip to content

doc: clarify the runc's threat model#5361

Open
lifubang wants to merge 1 commit into
opencontainers:mainfrom
lifubang:feat-threat-model
Open

doc: clarify the runc's threat model#5361
lifubang wants to merge 1 commit into
opencontainers:mainfrom
lifubang:feat-threat-model

Conversation

@lifubang

@lifubang lifubang commented Jul 7, 2026

Copy link
Copy Markdown
Member

We greatly appreciate the ongoing engagement of the security research community with runc.
By clarifying the threat model, we hope to make this collaboration as productive as possible,
and enable researchers to quickly determine whether a finding falls within runc’s scope,
so we can respond more swiftly and effectively.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR expands SECURITY.md with a detailed threat model for runc to help security researchers quickly determine what classes of issues are in-scope vs out-of-scope for reporting.

Changes:

  • Adds a new “Threat Model” section explaining runc’s role, security boundary, and trust assumptions around config.json.
  • Enumerates in-scope vs out-of-scope vulnerability classes, with concrete examples and a pre-reporting checklist.
  • Adds a small reference table of real-world runc CVEs.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread SECURITY.md
Comment thread SECURITY.md Outdated
Comment thread SECURITY.md Outdated
@lifubang
lifubang force-pushed the feat-threat-model branch from a0bcf3c to 91afa94 Compare July 7, 2026 04:47
Signed-off-by: lifubang <lifubang@acmcoder.com>
@lifubang
lifubang force-pushed the feat-threat-model branch from 91afa94 to 7929825 Compare July 7, 2026 05:17
@lifubang

lifubang commented Jul 7, 2026

Copy link
Copy Markdown
Member Author

The latest force push was related to the PoC.

@cyphar

cyphar commented Jul 7, 2026

Copy link
Copy Markdown
Member

I'll review this soon, but I should mention that @rata and I came up with some bullet points earlier this year for stuff we would need so he will certainly have some input as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants