GPU VulnDB

Database/Container, Kubernetes & orchestration

runc: Insufficient checks when bind-mounting /dev/console allow writes to arbitrary host procfs paths

CVE-2025-52565Container, Kubernetes & orchestrationcurated

Impact

Insufficient checks when bind-mounting /dev/console allow writes to arbitrary host procfs paths; container escape

Who can reach it

Any tenant workload / malicious image

What to do

Replace runc on all nodes; drain required to restart containers

Fleet impact

How widespread

Universal - same runc version range

Cost to remediate

node-drain - same as above; the fix ships in runc 1.2.8 / 1.3.3 / 1.4.0-rc.3 and only applies to newly created containers

Why it hits the whole fleet

/dev/console bind-mount race/symlink lets runc mount an unexpected target before LSM/mount protections apply, granting write access to procfs and a breakout

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.