CVE-2025-52565

CWE-61CWE-363CWE-5914 documents10 sources
Severity
8.4HIGH
EPSS
0.0%
top 95.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateNov 24

Description

runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H

Affected Packages6 packages

Gogithub.com/opencontainers/runc1.0.0-rc31.2.8+2
CVEListV5opencontainers/runc>= 1.0.0-rc3, < 1.2.8, >= 1.3.0-rc.1, < 1.3.3, >= 1.4.0-rc.1, < 1.4.0-rc.3+2
NVDlinuxfoundation/runc1.0.11.2.8+3
Debianrunc< 1.3.3+ds1-2
Ubunturunc-app< 1.3.3-0ubuntu1~22.04.2+2

Patches

🔴Vulnerability Details

7
OSV
runc-app, runc-stable regression2025-11-24
OSV
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc2025-11-18
OSV
CVE-2025-52565: runc is a CLI tool for spawning and running containers according to the OCI specification2025-11-06
CVEList
container escape due to /dev/console mount and related races2025-11-06
OSV
runc container escape with malicious config due to /dev/console mount and related races2025-11-05

📋Vendor Advisories

4
Microsoft
container escape due to /dev/console mount and related races2025-11-11
Red Hat
runc: container escape with malicious config due to /dev/console mount and related races2025-11-05
Ubuntu
runC vulnerabilities2025-11-04
Debian
CVE-2025-52565: runc - runc is a CLI tool for spawning and running containers according to the OCI spec...2025

🕵️Threat Intelligence

1
Bleepingcomputer
Dangerous runC flaws could allow hackers to escape Docker containers2025-11-09

💬Community

1
Bugzilla
CVE-2025-52565 runc: container escape with malicious config due to /dev/console mount and related races2025-10-17
CVE-2025-52565 (HIGH CVSS 8.4) | runc is a CLI tool for spawning and | cvebase.io