New runc vulnerabilities allow container escape: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881
ID: f25ee339-ca96-5c0a-ad1c-748c7e5ce4ce
STIX ID: report--f25ee339-ca96-5c0a-ad1c-748c7e5ce4ce
Feed Name: Sysdig Blog
On November 5, 2025, Sysdig Threat Research Team published an analysis of three critical runc vulnerabilities that allow container escape via maskedPaths abuse, /dev/console mount race conditions, and procfs write redirection (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881); these flaws can let an attacker using a crafted container or Dockerfile gain root on the host. The report details technical attack mechanisms, affected and fixed runc versions, experimental Falco detection rules for symlink-based exploitation, and recommended mitigations including upgrading runc, enabling user namespaces or rootless containers, and applying vendor patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
