GPU VulnDB

Database/Container, Kubernetes & orchestration

runc: Insufficient verification of masked-path bind mounts (/dev/null replaced by symlink) enables container

CVE-2025-31133Container, Kubernetes & orchestrationcurated

Impact

Insufficient verification of masked-path bind mounts (/dev/null replaced by symlink) enables container escape to host root

Who can reach it

Any tenant workload / malicious image with a custom mount config

What to do

Replace runc on all nodes; running containers stay vulnerable so drain required

Fleet impact

How widespread

Universal - all runc ≤1.2.7 / 1.3.2 / 1.4.0-rc.2

Cost to remediate

node-drain - binary replace plus recreation of every container; running containers are not retroactively protected

Why it hits the whole fleet

Replacing /dev/null in the container with a symlink into host /proc makes critical host procfs entries mount writable, yielding container escape to host root from a tenant-controlled image

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.