CVE-2025-31133 is a high-severity vulnerability affecting runc versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, and 1.4.0-rc.1 through 1.4.0-rc.2. The flaw stems from insufficient validation of bind-mount sources for /dev/null, enabling arbitrary mount gadgets. This can lead to host information disclosure, denial of service, container escape, or bypassing of maskedPaths, with a CVSS score of 7.8 (High) due to its low attack complexity and high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.8CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:* | ||
>= 1.3.0, < 1.3.3CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:* | ||
1.4.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:1.4.0:rc1:*:*:*:*:*:* | ||
1.4.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:1.4.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Container escape vulnerabilities in runc affecting Cloud Run
Nov 24, 2025runc container escape via "masked path" abuse due to mount race conditions
Nov 11, 2025Container escape vulnerabilities in runc affecting GKE
Nov 10, 2025runc container escape via "masked path" abuse due to mount race conditions
Nov 5, 2025runc: container escape via 'masked path' abuse due to mount race conditions
Nov 5, 2025Container escape vulnerabilities in runc affecting Cloud Run