Database/Container, Kubernetes & orchestration
runc: Insufficient verification of masked-path bind mounts (/dev/null replaced by symlink) enables container
Impact
Insufficient verification of masked-path bind mounts (/dev/null replaced by symlink) enables container escape to host root
Who can reach it
Any tenant workload / malicious image with a custom mount config
What to do
Replace runc on all nodes; running containers stay vulnerable so drain required
Fleet impact
How widespread
Universal - all runc ≤1.2.7 / 1.3.2 / 1.4.0-rc.2
Cost to remediate
node-drain - binary replace plus recreation of every container; running containers are not retroactively protected
Why it hits the whole fleet
Replacing /dev/null in the container with a symlink into host /proc makes critical host procfs entries mount writable, yielding container escape to host root from a tenant-controlled image
References
Related entries
- runc: Attacker misdirects runc writes to /proc via racing symlinksCVE-2025-52881 · runcHigh
- runc: Volume-mount race gives incorrect access control and privilege escalation to hostCVE-2019-19921 · runcHigh
- runc: Regression of CVE-2019-19921: incorrect access control leading to privilege escalation via volume mountsCVE-2023-27561 · runcHigh
- runc: AppArmor bypass when /proc inside the container is symlinked with a specific mount configCVE-2023-28642 · runcMedium
- runc: Netlink bytemsg length integer overflow in libcontainer allows config injection / partial escapeCVE-2021-43784 · runcMedium
- runc: `runc exec --cap` created processes with non-empty inheritable capabilitiesCVE-2022-29162 · runcMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.