Database/Container, Kubernetes & orchestration
runc: Attacker misdirects runc writes to /proc via racing symlinks
CVSS 7.3CVE-2025-52881Container, Kubernetes & orchestrationcurated
Impact
Attacker misdirects runc writes to /proc via racing symlinks; can defeat LSM labelling and escape
Who can reach it
Any tenant workload
What to do
Replace runc on all nodes; drain required
Fleet impact
How widespread
Universal - same runc version range
Cost to remediate
node-drain - runc upgrade + container recreation across the whole fleet
Why it hits the whole fleet
LSM (AppArmor/SELinux) bypass that makes arbitrary procfs writes easy, turning the other two into reliable host root; AWS, Alibaba and every distro shipped emergency runc rebuilds
References
Related entries
- runc: Volume-mount race gives incorrect access control and privilege escalation to hostCVE-2019-19921 · runcHigh
- runc: Regression of CVE-2019-19921: incorrect access control leading to privilege escalation via volume mountsCVE-2023-27561 · runcHigh
- runc: AppArmor bypass when /proc inside the container is symlinked with a specific mount configCVE-2023-28642 · runcMedium
- runc: Netlink bytemsg length integer overflow in libcontainer allows config injection / partial escapeCVE-2021-43784 · runcMedium
- runc: `runc exec --cap` created processes with non-empty inheritable capabilitiesCVE-2022-29162 · runcMedium
- runc: Rootless runc leaves /sys/fs/cgroup writable inside the containerCVE-2023-25809 · runcMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.