<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:19:40.487134+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:19927</id>
    <title>ALSA-2025:19927 — Important: runc security update</title>
    <updated>2026-10-03T22:19:41.380852+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: runc</p>
<p>The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.</p>
<p>Security Fix(es):</p>
<p>* runc: container escape via 'masked path' abuse due to mount race conditions (CVE-2025-31133)
  * runc: container escape with malicious config due to /dev/console mount and related races (CVE-2025-52565)
  * runc: container escape and denial of service due to arbitrary write gadgets and procfs write redirects (CVE-2025-52881)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:19927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-14042</id>
    <title>bdu:2025-14042</title>
    <updated>2026-10-03T22:19:41.380962+00:00</updated>
    <content>bdu:2025-14042</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-14042"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-52565</id>
    <title>BELL-CVE-2025-52565</title>
    <updated>2026-10-03T22:19:41.380997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: runc, Alpaquita:stream: runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-52565"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1129</id>
    <title>certfr-2025-avi-1129 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T22:19:41.381025+00:00</updated>
    <content>certfr-2025-avi-1129</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-260276</id>
    <title>EUVD-2026-260276</title>
    <updated>2026-10-03T22:19:41.381052+00:00</updated>
    <content>EUVD-2026-260276</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-260276"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52565</id>
    <title>fkie_cve-2025-52565</title>
    <updated>2026-10-03T22:19:41.381064+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of `/dev/pts/$n` to `/dev/console` as configured for all containers that allocate a console). This happens after `pivot_root(2)`, so this cannot be used to write to host files directly -- however, as with CVE-2025-31133, this can load to denial of service of the host or a container breakout by providing the attacker with a writable copy of `/proc/sysrq-trigger` or `/proc/sys/kernel/core_pattern` (respectively). This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-52565"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qw9x-cqr3-wc7r</id>
    <title>GHSA-qw9x-cqr3-wc7r — runc container escape with malicious config due to /dev/console mount and related races</title>
    <updated>2026-10-03T22:19:41.381094+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/opencontainers/runc</p>
<p>### Impact ###
This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of `/dev/pts/$n` to `/dev/console` as configured for all containers that allocate a console).</p>
<p>In runc version 1.0.0-rc3 and later, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This happens after `pivot_root(2)`, so this cannot be used to write to host files directly -- however, as with CVE-2025-31133, this can load to denial of service of the host or a container breakout by providing the attacker with a writable copy of `/proc/sysrq-trigger` or `/proc/sys/kernel/core_pattern` (respectively).</p>
<p>The reason that the attacker can gain write access to these files is because the `/dev/console` bind-mount happens before `maskedPaths` and `readonlyPaths` are applied.</p>
<p>#### Additional Findings ####
While investigating this issue, runc discovered some other theoretical issues that may or may not be exploitable, as well as taking the opportunity to fix some fairly well-known issues related to consoles.</p>
<p>##### Issue 1: Problematic Usage of `os.Create` #####
Go provides an `os.Create` function for creating files, which older code in runc (dating back to the original `libcontainer` from the early 2010s) had a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qw9x-cqr3-wc7r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-52565</id>
    <title>msrc_CVE-2025-52565 — container escape due to /dev/console mount and related races</title>
    <updated>2026-10-03T22:19:41.381169+00:00</updated>
    <content>msrc_CVE-2025-52565</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-52565"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2820</id>
    <title>OESA-2025-2820 — runc security update</title>
    <updated>2026-10-03T22:19:41.381187+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: runc, openEuler:22.03-LTS-SP3: runc, openEuler:22.03-LTS-SP4: runc, openEuler:24.03-LTS: runc, openEuler:24.03-LTS-SP1: runc, openEuler:24.03-LTS-SP2: runc</p>
<p>runc is a CLI tool for spawning and running containers according to the OCI specification.

Security Fix(es):</p>
<p>runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container&amp;apos;s /dev/null) was actually a real /dev/null inode when using the container&amp;apos;s /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.(CVE-2025-31133)</p>
<p>runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of `/dev/pts/$n` to `/dev/console` as configured for all containers that allocate a console). This happens after `pivot_root(2)`, so this cannot…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2820"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15705-1</id>
    <title>openSUSE-SU-2025:15705-1 — runc-1.3.3-1.1 on GA media</title>
    <updated>2026-10-03T22:19:41.381235+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc-1.3.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15705-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:21221</id>
    <title>RHBA-2025:21221 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.17.44 packages update</title>
    <updated>2026-10-03T22:19:41.381255+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc: container escape via 'masked path' abuse due to mount race conditions runc: container escape with malicious config due to /dev/console mount and related races</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:21221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:21036-1</id>
    <title>SUSE-SU-2025:21036-1 — Security update for runc</title>
    <updated>2026-10-03T22:19:41.381274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:21036-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-52565</id>
    <title>UBUNTU-CVE-2025-52565</title>
    <updated>2026-10-03T22:19:41.381302+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: runc, Ubuntu:Pro:18.04:LTS: runc, Ubuntu:20.04:LTS: runc, Ubuntu:20.04:LTS: runc-app, Ubuntu:22.04:LTS: runc, Ubuntu:22.04:LTS: runc-app, Ubuntu:24.04:LTS: runc, Ubuntu:24.04:LTS: runc-app, Ubuntu:25.10: runc, Ubuntu:25.10: runc-app and 1 more</p>
<p>runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of `/dev/pts/$n` to `/dev/console` as configured for all containers that allocate a console). This happens after `pivot_root(2)`, so this cannot be used to write to host files directly -- however, as with CVE-2025-31133, this can load to denial of service of the host or a container breakout by providing the attacker with a writable copy of `/proc/sysrq-trigger` or `/proc/sys/kernel/core_pattern` (respectively). This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-52565"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2518</id>
    <title>WID-SEC-W-2025-2518 — Red Hat Enterprise Linux (runc): Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T22:19:41.381345+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Red Hat OpenShift ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2518"/>
  </entry>
</feed>
