logo

New runc vulnerabilities allow container escape: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881

ID: 4e3f90b5-96be-5e65-a3a4-cc6de319f741

STIX ID: report--4e3f90b5-96be-5e65-a3a4-cc6de319f741

Feed Name: Sysdig Blog

Threat Score
70/100

Date Published: 2025-11-06

Date Updated: 2026-05-01

...
...

This Sysdig Threat Research Team advisory (Nov 5, 2025) details three runc vulnerabilities that enable container escape and arbitrary /proc writes via maskedPaths symlink abuse, /dev/console mount races, and shared-mount race conditions leading to LSM bypass; it lists affected and fixed runc versions, provides detection guidance (experimental Falco rule), and recommends immediate mitigations including upgrading runc, enabling user namespaces, and using rootless containers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.