Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
cloud-service-vulnerabilitywidely-deployed-product-advisoryproof-of-concept-release

Critical runC Vulnerabilities Enable Full Container Escape and Host Compromise

Updated 3mo agoFirst seen Nov 11, 20252 sources

Security researchers have disclosed three critical vulnerabilities in the runC container runtime, which is widely used in platforms such as Docker and Kubernetes. The flaws, identified as CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881, arise from logic and race-condition errors in runC's handling of temporary bind mounts, symbolic links, and certain write operations. Attackers can exploit these weaknesses to break container isolation, potentially gaining write access to sensitive host system files and kernel interfaces such as /proc/sys/kernel/core_pattern or /proc/sysrq-trigger, leading to full container escapes and even host-level compromise.

The vulnerabilities allow attackers to abuse masked paths, console bind-mounts, and redirected writes, bypassing standard hardening and isolation controls. Exploitation requires either custom mount configurations or the use of untrusted container images, but the risk is significant for orchestrated environments like Docker and Kubernetes. Security advisories from both the runC project and the U.S. National Vulnerability Database urge immediate updates to patched versions or the application of provided patches to mitigate these threats. The vulnerabilities highlight the importance of robust container runtime security and the potential impact of logic flaws in core infrastructure components.

Share:
Critical runC Vulnerabilities Enable Full Container Escape and Host Compromise
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Nov 10, 20258mo ago

Sysdig publishes detection rules for exploitation attempts

Sysdig released detection rules to help defenders identify attempts to exploit the runc vulnerabilities in containerized environments. The guidance accompanied broader recommendations to patch affected systems immediately, especially where untrusted images or custom mount configurations are used.

runc releases fixes for the container-escape flaws

The vulnerabilities were fixed in runc versions 1.2.8, 1.3.3, and 1.4.0-rc.3. The fixes address issues involving masked paths, console bind-mounts, and redirected writes that could bypass isolation controls such as SELinux and AppArmor.

Researchers discover three runc container-escape vulnerabilities

Security researchers identified three high-severity logic flaws in the runc container runtime, tracked as CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881. The bugs allow container escape and potential root-level access on Docker or Kubernetes hosts by abusing procfs-related write handling.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Affected products
1 linked
Docker
Organizations
8 linked
Open Container InitiativeKubernetesSuseruncSelinuxDockerApparmorSysdig
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.