New runc vulnerabilities allow container escape: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881
ID: 4e3f90b5-96be-5e65-a3a4-cc6de319f741
STIX ID: report--4e3f90b5-96be-5e65-a3a4-cc6de319f741
Feed Name: Sysdig Blog
Threat Score
This Sysdig Threat Research Team advisory (Nov 5, 2025) details three runc vulnerabilities that enable container escape and arbitrary /proc writes via maskedPaths symlink abuse, /dev/console mount races, and shared-mount race conditions leading to LSM bypass; it lists affected and fixed runc versions, provides detection guidance (experimental Falco rule), and recommends immediate mitigations including upgrading runc, enabling user namespaces, and using rootless containers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
