<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:55:48.469793+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:19927</id>
    <title>ALSA-2025:19927 — Important: runc security update</title>
    <updated>2026-10-03T17:55:49.236318+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: runc</p>
<p>The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.</p>
<p>Security Fix(es):</p>
<p>* runc: container escape via 'masked path' abuse due to mount race conditions (CVE-2025-31133)
  * runc: container escape with malicious config due to /dev/console mount and related races (CVE-2025-52565)
  * runc: container escape and denial of service due to arbitrary write gadgets and procfs write redirects (CVE-2025-52881)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:19927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-14041</id>
    <title>bdu:2025-14041</title>
    <updated>2026-10-03T17:55:49.236412+00:00</updated>
    <content>bdu:2025-14041</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-14041"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-31133</id>
    <title>BELL-CVE-2025-31133</title>
    <updated>2026-10-03T17:55:49.236431+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: runc, Alpaquita:stream: runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-31133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1129</id>
    <title>certfr-2025-avi-1129 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T17:55:49.236452+00:00</updated>
    <content>certfr-2025-avi-1129</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-pq07861</id>
    <title>CLEANSTART-2026-PQ07861 — Security fix for CVE-2025-31133 applied in: cadvisor 0.53.0-r0</title>
    <updated>2026-10-03T17:55:49.236468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: cadvisor</p>
<p>Security vulnerability affects the cadvisor package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-pq07861"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-260236</id>
    <title>EUVD-2026-260236</title>
    <updated>2026-10-03T17:55:49.236489+00:00</updated>
    <content>EUVD-2026-260236</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-260236"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-31133</id>
    <title>fkie_cve-2025-31133</title>
    <updated>2026-10-03T17:55:49.236500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-31133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9493-h29p-rfm2</id>
    <title>GHSA-9493-h29p-rfm2 — runc container escape via "masked path" abuse due to mount race conditions</title>
    <updated>2026-10-03T17:55:49.236524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/opencontainers/runc</p>
<p>### Impact ###  
The OCI runtime specification has a `maskedPaths` feature that allows for files or directories to be "masked" by placing a mount on top of them to conceal their contents. This is primarily intended to protect against privileged users in non-user-namespaced from being able to write to files or access directories that would either provide sensitive information about the host to containers or allow containers to perform destructive or other privileged operations on the host (examples include `/proc/kcore`, `/proc/timer_list`, `/proc/acpi`, and `/proc/keys`).</p>
<p>`maskedPaths` can be used to either mask a directory or a file -- directories are masked using a new read-only `tmpfs` instance that is mounted on top of the masked path, while files are masked by bind-mounting the container's `/dev/null` on top of the masked path.</p>
<p>In all known versions of runc, when using the container's `/dev/null` to mask files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's `/dev/null`) was actually a real `/dev/null` inode. While `/dev/null` is usually created by runc when doing container creation, it is possible for an attacker to create a `/dev/null` or modify the `/dev/null` inode created by runc through race conditions with other containers sharing mounts (runc has also verified this attack is possible to exploit using a standard Dockerfile with `docker buildx build` as that also permits triggering parallel execution of…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9493-h29p-rfm2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-31133</id>
    <title>msrc_CVE-2025-31133 — runc container escape via "masked path" abuse due to mount race conditions</title>
    <updated>2026-10-03T17:55:49.236590+00:00</updated>
    <content>msrc_CVE-2025-31133</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-31133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2820</id>
    <title>OESA-2025-2820 — runc security update</title>
    <updated>2026-10-03T17:55:49.236608+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: runc, openEuler:22.03-LTS-SP3: runc, openEuler:22.03-LTS-SP4: runc, openEuler:24.03-LTS: runc, openEuler:24.03-LTS-SP1: runc, openEuler:24.03-LTS-SP2: runc</p>
<p>runc is a CLI tool for spawning and running containers according to the OCI specification.

Security Fix(es):</p>
<p>runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container&amp;apos;s /dev/null) was actually a real /dev/null inode when using the container&amp;apos;s /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.(CVE-2025-31133)</p>
<p>runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of `/dev/pts/$n` to `/dev/console` as configured for all containers that allocate a console). This happens after `pivot_root(2)`, so this cannot…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2820"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15705-1</id>
    <title>openSUSE-SU-2025:15705-1 — runc-1.3.3-1.1 on GA media</title>
    <updated>2026-10-03T17:55:49.236654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc-1.3.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15705-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:21221</id>
    <title>RHBA-2025:21221 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.17.44 packages update</title>
    <updated>2026-10-03T17:55:49.236673+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc: container escape via 'masked path' abuse due to mount race conditions runc: container escape with malicious config due to /dev/console mount and related races</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:21221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:21036-1</id>
    <title>SUSE-SU-2025:21036-1 — Security update for runc</title>
    <updated>2026-10-03T17:55:49.236692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:21036-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-31133</id>
    <title>UBUNTU-CVE-2025-31133</title>
    <updated>2026-10-03T17:55:49.236707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: runc, Ubuntu:Pro:18.04:LTS: runc, Ubuntu:20.04:LTS: runc, Ubuntu:20.04:LTS: runc-app, Ubuntu:22.04:LTS: runc, Ubuntu:22.04:LTS: runc-app, Ubuntu:24.04:LTS: runc, Ubuntu:24.04:LTS: runc-app, Ubuntu:25.10: runc, Ubuntu:25.10: runc-app and 1 more</p>
<p>runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-31133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2518</id>
    <title>WID-SEC-W-2025-2518 — Red Hat Enterprise Linux (runc): Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T17:55:49.236743+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Red Hat OpenShift ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2518"/>
  </entry>
</feed>
