INFSA-2025:20957: runc security update

Information about definition

Identificator: INFSA-2025:20957

Type: security

Release date: 2025-12-01 14:28:52 UTC

Information about package

The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.

Vulnerabilities description

  • CVE-2025-31133

    A flaw was found in runc. This flaw exploits an issue with how masked paths are implementedin runc. When masking files, runc will bind-mount the container's /dev/null inode on top of the file. However, if an attacker can replace /dev/null with a symlink to some other procfs file, runc will instead bind-mount the symlink target read-write.

  • CVE-2025-52565

    A flaw exploits an issue in /dev/console bind-mounts. When creating the /dev/console bind-mount (to /dev/pts/$n), if an attacker replaces /dev/pts/$n with a symlink then runc will bind-mount the symlink target over /dev/console.

  • CVE-2025-52881

    A flaw was found in runc. This is a flaw that allowed an attacker to trick runc into writing the LSM process labels for a container process into a dummy tmpfs file and thus not apply the correct LSM labels to the container process.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 8.2 no information
no information 8.2 no information
no information 8.2 no information
Critical, important, moderate, low

Updated packages

loader icon Preparing to download...
Architecture: Download