URL has been copied successfully!
Researchers Uncover Critical runC Bugs Allowing Full Container Escape
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Researchers Uncover Critical runC Bugs Allowing Full Container Escape

Security researchers have revealed three serious vulnerabilities in runC, the Open Container Initiative (OCI)-compliant runtime that powers platforms such as Docker and Kubernetes, which could allow attackers to break container isolation and gain control of the host system. The flaws, tracked as CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881, stem from weaknesses in how runC manages temporary bind mounts, symbolic links (symlinks), and certain write operations. Together, they can be exploited to achieve complete container escapes and even host-level compromises.

First seen on thecyberexpress.com

Jump to article: thecyberexpress.com/cve-2025-31133-runc-container-security/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link