PT-2025-45350 · Runc+10 · Runc+10
CVE-2025-31133
·
Published
2025-11-04
·
Updated
2026-09-01
CVSS v3.1
7.8
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
runc versions 1.2.0 through 1.2.7
runc versions 1.3.0-rc.1 through 1.3.1
runc versions 1.4.0-rc.1 through 1.4.0-rc.2
Description
An issue exists in the
maskedPaths function where insufficient verification of the bind-mount source occurs when using the container's /dev/null to mask. This creates a race condition that allows symlink following, enabling an arbitrary mount gadget. This can lead to container escape, host information disclosure, host denial of service, or the bypassing of maskedPaths.Recommendations
Update versions 1.2.0 through 1.2.7 to version 1.2.8.
Update versions 1.3.0-rc.1 through 1.3.1 to version 1.3.3.
Update versions 1.4.0-rc.1 through 1.4.0-rc.2 to version 1.4.0-rc.3.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Runc