GPU VulnDB

Database/Container, Kubernetes & orchestration

runc: Attacker misdirects runc writes to /proc via racing symlinks

CVE-2025-52881Container, Kubernetes & orchestrationcurated

Impact

Attacker misdirects runc writes to /proc via racing symlinks; can defeat LSM labelling and escape

Who can reach it

Any tenant workload

What to do

Replace runc on all nodes; drain required

Fleet impact

How widespread

Universal - same runc version range

Cost to remediate

node-drain - runc upgrade + container recreation across the whole fleet

Why it hits the whole fleet

LSM (AppArmor/SELinux) bypass that makes arbitrary procfs writes easy, turning the other two into reliable host root; AWS, Alibaba and every distro shipped emergency runc rebuilds

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.