Critical runc Vulnerabilities Put Docker and Kubernetes Container Isolation at Risk
Three critical vulnerabilities in runc, the container runtime powering Docker, Kubernetes, and other containerization platforms.
These flaws could allow attackers to escape container isolation and gain root access to host systems. However, no active exploits have been detected yet.
The vulnerabilities leverage race mount conditions and procfs write redirects to break out of container boundaries.
Attackers need the ability to start containers with custom mount configurations, making malicious container images and Dockerfiles the primary attack vectors.
The Sysdig Threat Research Team analyzed all three vulnerabilities and provided detailed mitigation recommendations for affected organizations worldwide.
CVE-2025-31133 exploits weaknesses in runc’s maskedPaths feature, which protects sensitive host files from container access.
CVE-2025-52565 targets the /dev/console mount operation during container initialization.
Insufficient validation allows attackers to redirect mounts and gain write access to protected procfs files.
The attack succeeds because the mount happens before maskedPaths and readonlyPaths protections are correctly applied.
CVE-2025-52881 enables attackers to bypass Linux Security Module protections through race conditions with shared mounts.
Attackers can redirect runc writes to fake procfs files and manipulate dangerous system files such as/proc/sysrq-trigger or /proc/sys/kernel/core_pattern, potentially crashing systems or escaping from containers.
CVE-2025-31133 and CVE-2025-52881 impact all known runc versions, while CVE-2025-52565 affects versions 1.0.0-rc3 and later.
All three vulnerabilities are patched in runc versions 1.2.8, 1.3.3, and 1.4.0-rc.3 or later.
Organizations using containerized environments should immediately update Runc to patched versions.
The Sysdig Threat Research Team recommends enabling user namespaces for all containers, which blocks critical attack vectors by restricting access to the procfs file system.
Using rootless containers further limits the scope of vulnerability. Cloud providers, including AWS, ECS, and EKS, released security updates on November 5, 2025.
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Elastic has disclosed a significant security vulnerability in Elastic Defend for Windows that could allow…
Black Friday 2025 represents the most dangerous shopping season in cybercrime history, with fraudsters leveraging…
MAD-CAT (Meow Attack Data Corruption Automation Tool) targets MongoDB, Elasticsearch, Cassandra, Redis, CouchDB, and Hadoop…
A critical remote code execution vulnerability in Monsta FTP, a popular web-based FTP client used…
HackGPT Enterprise is a new tool made for security teams focuses on being scalable and…
Welcome to this week's edition of the Cybersecurity News Weekly , where we dissect the…
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
