Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-31133

31
FAUCET Score

CVE-2025-31133 is a high-severity vulnerability affecting runc versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, and 1.4.0-rc.1 through 1.4.0-rc.2. The flaw stems from insufficient validation of bind-mount sources for /dev/null, enabling arbitrary mount gadgets. This can lead to host information disclosure, denial of service, container escape, or bypassing of maskedPaths, with a CVSS score of 7.8 (High) due to its low attack complexity and high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.2.8CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*
>= 1.3.0, < 1.3.3CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*
1.4.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:1.4.0:rc1:*:*:*:*:*:*
1.4.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:1.4.0:rc2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.3HIGH

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.73%
Probability of exploitation in next 30 days
EPSS Percentile
50.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0073 is in the 87th percentile among its peer group of 1,525 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (28)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/opencontainers/runcFixed in: 1.2.8
gopatch availablevia ghsa
Product: github.com/opencontainers/runcFixed in: 1.3.3
gopatch availablevia ghsa
Product: github.com/opencontainers/runcFixed in: 1.4.0-rc.3
microsoftpatch availablevia msrc
Product: azl3 kubernetes 1.30.10-14 on Azure Linux 3.0Fixed in: 1.30.10-15
microsoftpatch availablevia msrc
Product: 20659-17086Fixed in: 1.2.8-1
microsoftpatch availablevia msrc
Product: 20364-17086Fixed in: 1.28.4-20
microsoftpatch availablevia msrc
Product: 20624-17084Fixed in: 1.30.10-15
microsoftpatch availablevia msrc
Product: cbl2 moby-runc 1.1.9-9 on CBL Mariner 2.0Fixed in: 1.2.8-1
microsoftpatch availablevia msrc
Product: cbl2 kubernetes 1.28.4-19 on CBL Mariner 2.0Fixed in: 1.28.4-20
netgearpatch availablevia llm_extracted
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: runc-4:1.2.9-1.rhaos4.16.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: runc-4:1.2.9-1.rhaos4.16.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: rhcos-415.92.202512100122-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: runc-4:1.2.9-1.rhaos4.16.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: rhcos-416.94.202511191934-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: runc-4:1.2.9-1.rhaos4.17.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: runc-4:1.2.9-1.rhaos4.18.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: rhcos-418.94.202511170715-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Quay 3.16Fixed in: quay/quay-builder-rhel9:sha256:76354449e4e8b67bfbbfae10337b7d50fc657c909c8798fddb95dee408c3a9f2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:rhel8-8100020251112161627.afee755d
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: runc-4:1.2.9-1.rhaos4.16.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: rhcos-413.92.202511261311-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: runc-4:1.2.5-3.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: runc-4:1.3.0-4.el9_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: runc-4:1.2.9-1.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.12Fixed in: runc-4:1.2.9-1.rhaos4.17.el8
View patch
sophospatch availablevia llm_extracted
View patch

Vendor Advisories (6)

sophosllm-sophos-077a4932b2b5cecbHIGH

Container escape vulnerabilities in runc affecting Cloud Run

Nov 24, 2025
microsoft2025-Nov/CVE-2025-31133Important

runc container escape via "masked path" abuse due to mount race conditions

Nov 11, 2025
sophosllm-sophos-cc1ca14288cc9f8eHIGH

Container escape vulnerabilities in runc affecting GKE

Nov 10, 2025
goGHSA-9493-h29p-rfm2high

runc container escape via "masked path" abuse due to mount race conditions

Nov 5, 2025
redhatCVE-2025-31133Important

runc: container escape via 'masked path' abuse due to mount race conditions

Nov 5, 2025
netgearllm-netgear-e9294559ad30d4a3HIGH

Container escape vulnerabilities in runc affecting Cloud Run

References

github.com / opencontainers/runc/commit/1a30a8f3d921acbbb6a4bb7e99da2c05f8d48522
Patch
github.com / opencontainers/runc/commit/5d7b2424072449872d1cd0c937f2ca25f418eb66
Patch
github.com / opencontainers/runc/commit/8476df83b534a2522b878c0507b3491def48db9f
Patch
github.com / opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64
Patch
github.com / opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2
MitigationPatchThird Party Advisory