logo

Dangerous runC flaws could allow hackers to escape Docker containers

ID: f35e4da2-a53a-5439-b203-09a06bdd2835

STIX ID: report--f35e4da2-a53a-5439-b203-09a06bdd2835

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-11-09

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Three critical vulnerabilities in the runC container runtime (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) can be exploited to bypass container isolation by abusing bind-mounts and symlink/race conditions to write to /proc and other host targets, potentially giving attackers root on the underlying host; patches are available and mitigations include enabling user namespaces and running rootless containers, and there are no confirmed active exploits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.