CVE-2025-52881

CWE-61CWE-363CWE-5912 documents9 sources
Severity
7.3HIGH
EPSS
0.0%
top 96.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateNov 18

Description

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Affected Packages5 packages

Gogithub.com/opencontainers/runc1.3.0-rc.11.3.3+2
CVEListV5opencontainers/runc1.2.7, < 1.2.8+2
NVDlinuxfoundation/runc1.3.01.3.3+2
Debianrunc< 1.3.3+ds1-2

Patches

🔴Vulnerability Details

6
OSV
Container escape and DDoS due to arbitrary write gadgets and procfs write redirects in github.com/opencontainers/runc2025-11-18
CVEList
runc: LSM labels can be bypassed with malicious config using dummy procfs files2025-11-06
OSV
CVE-2025-52881: runc is a CLI tool for spawning and running containers according to the OCI specification2025-11-06
GHSA
runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects2025-11-05
OSV
runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects2025-11-05

📋Vendor Advisories

4
Microsoft
runc: LSM labels can be bypassed with malicious config using dummy procfs files2025-11-11
Red Hat
runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects2025-11-05
Ubuntu
runC vulnerabilities2025-11-04
Debian
CVE-2025-52881: runc - runc is a CLI tool for spawning and running containers according to the OCI spec...2025

🕵️Threat Intelligence

1
Bleepingcomputer
Dangerous runC flaws could allow hackers to escape Docker containers2025-11-09
CVE-2025-52881 (HIGH CVSS 7.3) | runc is a CLI tool for spawning and | cvebase.io