CVE-2025-52565 is a critical vulnerability in runc versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, affecting the Linux Foundation's runc container runtime. This flaw, similar to CVE-2025-31133, allows an attacker to trick runc into bind-mounting sensitive paths to writable locations within a container due to insufficient checks during the bind-mounting of /dev/pts/$n to /dev/console. With a CVSS score of 7.5 (HIGH), successful exploitation can lead to host denial of service or container escape by providing access to critical host files like /proc/sysrq-trigger or /proc/sys/kernel/core_pattern. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with 7 mentions and 7 media articles, indicating high awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.1, < 1.2.8CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:* | ||
>= 1.3.0, < 1.3.3CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:1.0.0:rc3:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:1.0.0:rc4:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:runc:1.0.0:rc5:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.2 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.5 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Container escape vulnerabilities in runc affecting Cloud Run
Nov 24, 2025container escape due to /dev/console mount and related races
Nov 11, 2025Container escape vulnerabilities in runc affecting GKE
Nov 10, 2025runc container escape with malicious config due to /dev/console mount and related races
Nov 5, 2025runc: container escape with malicious config due to /dev/console mount and related races
Nov 5, 2025Container escape vulnerabilities in runc affecting Cloud Run