PT-2025-45373 · Runc+10 · Runc+10
Published
2025-11-04
·
Updated
2026-05-01
·
CVE-2025-52565
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
runc versions 1.0.0-rc3 through 1.2.7
runc versions 1.3.0-rc.1 through 1.3.2
runc versions 1.4.0-rc.1 through 1.4.0-rc.2
Description
Insufficient checks when bind-mounting
/dev/pts/$n to /dev/console inside a container allow an attacker to trick the system into bind-mounting paths that are typically read-only or masked onto a writable path. This occurs after the pivot root(2) function is called, preventing direct writes to host files. However, it can lead to a host denial of service or a container breakout by providing the attacker with a writable copy of /proc/sysrq-trigger or /proc/sys/kernel/core pattern.Recommendations
Update to version 1.2.8
Update to version 1.3.3
Update to version 1.4.0-rc.3
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Runc