PT-2025-45373 · Runc+10 · Runc+10

Published

2025-11-04

·

Updated

2026-05-01

·

CVE-2025-52565

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions runc versions 1.0.0-rc3 through 1.2.7 runc versions 1.3.0-rc.1 through 1.3.2 runc versions 1.4.0-rc.1 through 1.4.0-rc.2
Description Insufficient checks when bind-mounting /dev/pts/$n to /dev/console inside a container allow an attacker to trick the system into bind-mounting paths that are typically read-only or masked onto a writable path. This occurs after the pivot root(2) function is called, preventing direct writes to host files. However, it can lead to a host denial of service or a container breakout by providing the attacker with a writable copy of /proc/sysrq-trigger or /proc/sys/kernel/core pattern.
Recommendations Update to version 1.2.8 Update to version 1.3.3 Update to version 1.4.0-rc.3

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

ALSA-2025:19927
ALSA-2025:20957
ALSA-2025:21232
AZL-69821
AZL-70513
AZL-70589
BDU:2025-14042
CESA-2025_21232
CVE-2025-52565
ECHO-77DD-C8A1-F292
GHSA-QW9X-CQR3-WC7R
GO-2025-4097
INFSA-2025_19927
INFSA-2025_20957
INFSA-2025_21232
MGASA-2025-0271
OPENSUSE-SU-2025:15705-1
OPENSUSE-SU-2025:20072-1
OPENSUSE-SU-2026:20072-1
OPENSUSE-SU-2026:20080-1
OPENSUSE-SU-2026:20140-1
OPENSUSE-SU-2026:20305-1
RHSA-2025:19927
RHSA-2025:20957
RHSA-2025:21232
RHSA-2025:21328
RHSA-2025_19927
RHSA-2025_20957
RHSA-2025_21232
RHSA-2026:0315
RHSA-2026:0331
RHSA-2026:0418
RHSA-2026:0425
RHSA-2026:0676
RHSA-2026:0701
RHSA-2026:0995
RHSA-2026:10703
RHSA-2026:1540
RHSA-2026:4531
RHSA-2026:4693
RHSA-2026:8325
SUSE-SU-2025:21036-1
SUSE-SU-2025:21038-1
SUSE-SU-2025:21054-1
SUSE-SU-2025:21072-1
SUSE-SU-2025:21136-1
SUSE-SU-2025:3950-1
SUSE-SU-2025:3951-1
SUSE-SU-2025:4073-1
SUSE-SU-2025:4073-2
SUSE-SU-2025:4077-1
SUSE-SU-2025:4079-1
SUSE-SU-2025:4080-1
SUSE-SU-2025:4081-1
SUSE-SU-2026:0327-1
SUSE-SU-2026:20103-1
SUSE-SU-2026:20116-1
SUSE-SU-2026:20123-1
SUSE-SU-2026:20214-1
SUSE-SU-2026:20626-1
SUSE-SU-2026:20641-1
SUSE-SU-2026:21291-1
USN-7851-1
USN-7851-2

Affected Products

Alt Linux
Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Runc