{"id":"USN-7851-1","summary":"runc-app, runc-stable vulnerabilities","details":"Lei Wang and Li Fubang discovered that runC incorrectly handled masked\npaths. An attacker could possibly replace a container's /dev/null\nwith a symlink to some other procfs file and possibly escape a container.\n(CVE-2025-31133)\n\nLei Wang and Li Fubang discovered that runC incorrectly handled the\n/dev/console bind-mounts. An attacker could potentially exploit this issue\nto build-mount a symlink and escape a container. (CVE-2025-52565)\n\nLi Fubang and Tõnis Tiigi discovered that the fix for CVE-2019-16884 was\nincomplete. An attacker could possibly use this issue to cause a denial of\nservice or escape the container. (CVE-2025-52881)","modified":"2026-02-10T04:50:20Z","published":"2025-11-04T15:36:31Z","related":["UBUNTU-CVE-2025-31133","UBUNTU-CVE-2025-52565","UBUNTU-CVE-2025-52881"],"upstream":["CVE-2025-31133","CVE-2025-52565","CVE-2025-52881","UBUNTU-CVE-2025-31133","UBUNTU-CVE-2025-52565","UBUNTU-CVE-2025-52881"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7851-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-31133"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-52565"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-52881"}],"affected":[{"package":{"name":"runc-app","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/runc-app@1.3.3-0ubuntu1~22.04.2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.3-0ubuntu1~22.04.2"}]}],"versions":["1.1.12-0ubuntu2~22.04.1","1.2.5-0ubuntu1~22.04.1","1.3.0-0ubuntu2~22.04.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"runc","binary_version":"1.3.3-0ubuntu1~22.04.2"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2025-31133","severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","type":"CVSS_V4"},{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2025-52565","severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H","type":"CVSS_V4"},{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2025-52881","severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","type":"CVSS_V4"},{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:22.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7851-1.json"}},{"package":{"name":"runc-app","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/runc-app@1.3.3-0ubuntu1~24.04.2?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.3-0ubuntu1~24.04.2"}]}],"versions":["1.1.10-0ubuntu1","1.1.12-0ubuntu1","1.1.12-0ubuntu2","1.1.12-0ubuntu3","1.1.12-0ubuntu3.1","1.2.5-0ubuntu1~24.04.1","1.3.0-0ubuntu2~24.04.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"1.3.3-0ubuntu1~24.04.2","binary_name":"runc"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2025-31133","severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","type":"CVSS_V4"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2025-52565","severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H","type":"CVSS_V4"},{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"high"}]},{"severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","type":"CVSS_V4"},{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}],"id":"CVE-2025-52881"}],"ecosystem":"Ubuntu:24.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7851-1.json"}},{"package":{"name":"runc-app","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/runc-app@1.3.3-0ubuntu1~25.10.2?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.3-0ubuntu1~25.10.2"}]}],"versions":["1.2.5-0ubuntu1","1.3.0-0ubuntu1","1.3.0-0ubuntu2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"runc","binary_version":"1.3.3-0ubuntu1~25.10.2"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:25.10","cves":[{"id":"CVE-2025-31133","severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","type":"CVSS_V4"},{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2025-52565","severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H","type":"CVSS_V4"},{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2025-52881","severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","type":"CVSS_V4"},{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7851-1.json"}},{"package":{"name":"runc-stable","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/runc-stable@1.3.3-0ubuntu1~25.10.2?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.3-0ubuntu1~25.10.2"}]}],"versions":["1.3.0-0ubuntu1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"runc-stable","binary_version":"1.3.3-0ubuntu1~25.10.2"}]},"database_specific":{"cves_map":{"cves":[{"severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","type":"CVSS_V4"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"},{"score":"high","type":"Ubuntu"}],"id":"CVE-2025-31133"},{"id":"CVE-2025-52565","severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H","type":"CVSS_V4"},{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2025-52881","severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","type":"CVSS_V4"},{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:25.10"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7851-1.json"}}],"schema_version":"1.7.3"}