Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-52565

30
FAUCET Score

CVE-2025-52565 is a critical vulnerability in runc versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, affecting the Linux Foundation's runc container runtime. This flaw, similar to CVE-2025-31133, allows an attacker to trick runc into bind-mounting sensitive paths to writable locations within a container due to insufficient checks during the bind-mounting of /dev/pts/$n to /dev/console. With a CVSS score of 7.5 (HIGH), successful exploitation can lead to host denial of service or container escape by providing access to critical host files like /proc/sysrq-trigger or /proc/sys/kernel/core_pattern. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with 7 mentions and 7 media articles, indicating high awareness of its potential impact.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.1, < 1.2.8CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*
>= 1.3.0, < 1.3.3CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:*:*:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:1.0.0:rc3:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:1.0.0:rc4:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:runc:1.0.0:rc5:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.4HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.57%
Probability of exploitation in next 30 days
EPSS Percentile
43.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0057 is in the 92nd percentile among its peer group of 39 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.2 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.5 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (33)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/opencontainers/runcFixed in: 1.2.8
gopatch availablevia ghsa
Product: github.com/opencontainers/runcFixed in: 1.3.3
gopatch availablevia ghsa
Product: github.com/opencontainers/runcFixed in: 1.4.0-rc.3
microsoftpatch availablevia msrc
Product: cbl2 moby-runc 1.1.9-9 on CBL Mariner 2.0Fixed in: 1.2.8-1
microsoftpatch availablevia msrc
Product: 20659-17086Fixed in: 1.2.8-1
microsoftpatch availablevia msrc
Product: 20624-17084Fixed in: 1.30.10-15
microsoftpatch availablevia msrc
Product: azl3 kubernetes 1.30.10-14 on Azure Linux 3.0Fixed in: 1.30.10-15
netgearpatch availablevia llm_extracted
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: runc-4:1.2.9-1.rhaos4.16.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: rhcos-413.92.202511261311-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: runc-4:1.2.9-1.rhaos4.16.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: runc-4:1.2.9-1.rhaos4.16.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: rhcos-415.92.202512100122-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: runc-4:1.2.9-1.rhaos4.16.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: rhcos-416.94.202511191934-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: runc-4:1.2.9-1.rhaos4.17.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: runc-4:1.2.9-1.rhaos4.18.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: rhcos-418.94.202511170715-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-cuda-rhel9:sha256:bddcf7ab6d576572b6d60822c313ffebcd9869e4fde93e32ac327821f93cf32b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-rocm-rhel9:sha256:7856bdb7ae0d643a7b9362c164d4d4fe3c0c7186f5fff73a7ae9835b3df52e57
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/model-opt-cuda-rhel9:sha256:14e32e88f1b89f59ed34a6d712746b82a6a54c6ed4727784f18aeff853abbdc7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/model-opt-cuda-rhel9:sha256:fca12d55fef49b9a67c8aa7c2c004adb8916b9784134b4e571067a615a7a4a2e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-cuda-rhel9:sha256:f0ab1b678e9447eae4b6b2fe5c58531aa8524133db157f196726164e4dc20492
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-rocm-rhel9:sha256:e3b3efcdd86f60b90664a249d45918b2ac5f45bae5eed5399e310d63e878b287
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-tpu-rhel9:sha256:64796b48c68d31973a08e22c9530c39b1bc3ba9f376bbefa57643ef0fc857534
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-rocm-rhel9:sha256:c5efe40fa2a6e98d7d3d6676befff0dbbd87b2887769bb7e5856c5b0b0ada125
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: runc-4:1.2.9-1.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.12Fixed in: runc-4:1.2.9-1.rhaos4.17.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:rhel8-8100020251112161627.afee755d
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: runc-4:1.2.5-3.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: runc-4:1.3.0-4.el9_7
View patch
sophospatch availablevia llm_extracted
View patch

Vendor Advisories (6)

sophosllm-sophos-077a4932b2b5cecbHIGH

Container escape vulnerabilities in runc affecting Cloud Run

Nov 24, 2025
microsoft2025-Nov/CVE-2025-52565Important

container escape due to /dev/console mount and related races

Nov 11, 2025
sophosllm-sophos-cc1ca14288cc9f8eHIGH

Container escape vulnerabilities in runc affecting GKE

Nov 10, 2025
goGHSA-qw9x-cqr3-wc7rhigh

runc container escape with malicious config due to /dev/console mount and related races

Nov 5, 2025
redhatCVE-2025-52565Important

runc: container escape with malicious config due to /dev/console mount and related races

Nov 5, 2025
netgearllm-netgear-e9294559ad30d4a3HIGH

Container escape vulnerabilities in runc affecting Cloud Run

References

github.com / opencontainers/runc/commit/01de9d65dc72f67b256ef03f9bfb795a2bf143b4
Patch
github.com / opencontainers/runc/commit/398955bccb7f20565c224a3064d331c19e422398
Patch
github.com / opencontainers/runc/commit/531ef794e4ecd628006a865ad334a048ee2b4b2e
Patch
github.com / opencontainers/runc/commit/9be1dbf4ac67d9840a043ebd2df5c68f36705d1d
Patch
github.com / opencontainers/runc/commit/aee7d3fe355dd02939d44155e308ea0052e0d53a
Patch
github.com / opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64
Patch
github.com / opencontainers/runc/commit/de87203e625cd7a27141fb5f2ad00a320c69c5e8
Patch
github.com / opencontainers/runc/commit/ff94f9991bd32076c871ef0ad8bc1b763458e480
Patch
github.com / opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r
ExploitMitigationPatchThird Party Advisory