<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:47:36 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:19927 — Important: runc security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:19927</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: runc&lt;/p&gt;
&lt;p&gt;The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* runc: container escape via &amp;#39;masked path&amp;#39; abuse due to mount race conditions (CVE-2025-31133)
  * runc: container escape with malicious config due to /dev/console mount and related races (CVE-2025-52565)
  * runc: container escape and denial of service due to arbitrary write gadgets and procfs write redirects (CVE-2025-52881)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: runc&lt;/p&gt;
&lt;p&gt;The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* runc: container escape via &amp;#39;masked path&amp;#39; abuse due to mount race conditions (CVE-2025-31133)
  * runc: container escape with malicious config due to /dev/console mount and related races (CVE-2025-52565)
  * runc: container escape and denial of service due to arbitrary write gadgets and procfs write redirects (CVE-2025-52881)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:19927</guid>
    </item>
    <item>
      <title>bdu:2025-14041</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14041</link>
      <description>bdu:2025-14041</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14041</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-31133</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-31133</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: runc, Alpaquita:stream: runc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: runc, Alpaquita:stream: runc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-31133</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1129 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1129</link>
      <description>certfr-2025-avi-1129</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1129</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-PQ07861 — Security fix for CVE-2025-31133 applied in: cadvisor 0.53.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-pq07861</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cadvisor&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the cadvisor package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cadvisor&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the cadvisor package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-pq07861</guid>
    </item>
    <item>
      <title>EUVD-2026-260236</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260236</link>
      <description>EUVD-2026-260236</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260236</guid>
    </item>
    <item>
      <title>fkie_cve-2025-31133</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-31133</link>
      <description>&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container&amp;#39;s /dev/null) was actually a real /dev/null inode when using the container&amp;#39;s /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container&amp;#39;s /dev/null) was actually a real /dev/null inode when using the container&amp;#39;s /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-31133</guid>
    </item>
    <item>
      <title>GHSA-9493-h29p-rfm2 — runc container escape via "masked path" abuse due to mount race conditions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9493-h29p-rfm2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/opencontainers/runc&lt;/p&gt;
&lt;p&gt;### Impact ###  
The OCI runtime specification has a `maskedPaths` feature that allows for files or directories to be &amp;#34;masked&amp;#34; by placing a mount on top of them to conceal their contents. This is primarily intended to protect against privileged users in non-user-namespaced from being able to write to files or access directories that would either provide sensitive information about the host to containers or allow containers to perform destructive or other privileged operations on the host (examples include `/proc/kcore`, `/proc/timer_list`, `/proc/acpi`, and `/proc/keys`).&lt;/p&gt;
&lt;p&gt;`maskedPaths` can be used to either mask a directory or a file -- directories are masked using a new read-only `tmpfs` instance that is mounted on top of the masked path, while files are masked by bind-mounting the container&amp;#39;s `/dev/null` on top of the masked path.&lt;/p&gt;
&lt;p&gt;In all known versions of runc, when using the container&amp;#39;s `/dev/null` to mask files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container&amp;#39;s `/dev/null`) was actually a real `/dev/null` inode. While `/dev/null` is usually created by runc when doing container creation, it is possible for an attacker to create a `/dev/null` or modify the `/dev/null` inode created by runc through race conditions with other containers sharing mounts (runc has also verified this attack is possible to exploit using a standard Dockerfile with `docker buildx build` as that also permits triggering parallel execution of…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/opencontainers/runc&lt;/p&gt;
&lt;p&gt;### Impact ###  
The OCI runtime specification has a `maskedPaths` feature that allows for files or directories to be &amp;#34;masked&amp;#34; by placing a mount on top of them to conceal their contents. This is primarily intended to protect against privileged users in non-user-namespaced from being able to write to files or access directories that would either provide sensitive information about the host to containers or allow containers to perform destructive or other privileged operations on the host (examples include `/proc/kcore`, `/proc/timer_list`, `/proc/acpi`, and `/proc/keys`).&lt;/p&gt;
&lt;p&gt;`maskedPaths` can be used to either mask a directory or a file -- directories are masked using a new read-only `tmpfs` instance that is mounted on top of the masked path, while files are masked by bind-mounting the container&amp;#39;s `/dev/null` on top of the masked path.&lt;/p&gt;
&lt;p&gt;In all known versions of runc, when using the container&amp;#39;s `/dev/null` to mask files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container&amp;#39;s `/dev/null`) was actually a real `/dev/null` inode. While `/dev/null` is usually created by runc when doing container creation, it is possible for an attacker to create a `/dev/null` or modify the `/dev/null` inode created by runc through race conditions with other containers sharing mounts (runc has also verified this attack is possible to exploit using a standard Dockerfile with `docker buildx build` as that also permits triggering parallel execution of…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9493-h29p-rfm2</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-31133 — runc container escape via "masked path" abuse due to mount race conditions</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-31133</link>
      <description>msrc_CVE-2025-31133</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-31133</guid>
    </item>
    <item>
      <title>OESA-2025-2820 — runc security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2820</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: runc, openEuler:22.03-LTS-SP3: runc, openEuler:22.03-LTS-SP4: runc, openEuler:24.03-LTS: runc, openEuler:24.03-LTS-SP1: runc, openEuler:24.03-LTS-SP2: runc&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container&amp;amp;apos;s /dev/null) was actually a real /dev/null inode when using the container&amp;amp;apos;s /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.(CVE-2025-31133)&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of `/dev/pts/$n` to `/dev/console` as configured for all containers that allocate a console). This happens after `pivot_root(2)`, so this cannot…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: runc, openEuler:22.03-LTS-SP3: runc, openEuler:22.03-LTS-SP4: runc, openEuler:24.03-LTS: runc, openEuler:24.03-LTS-SP1: runc, openEuler:24.03-LTS-SP2: runc&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container&amp;amp;apos;s /dev/null) was actually a real /dev/null inode when using the container&amp;amp;apos;s /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.(CVE-2025-31133)&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of `/dev/pts/$n` to `/dev/console` as configured for all containers that allocate a console). This happens after `pivot_root(2)`, so this cannot…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2820</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15705-1 — runc-1.3.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15705-1</link>
      <description>&lt;p&gt;runc-1.3.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;runc-1.3.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15705-1</guid>
    </item>
    <item>
      <title>RHBA-2025:21221 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.17.44 packages update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2025:21221</link>
      <description>&lt;p&gt;runc: container escape via &amp;#39;masked path&amp;#39; abuse due to mount race conditions runc: container escape with malicious config due to /dev/console mount and related races&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;runc: container escape via &amp;#39;masked path&amp;#39; abuse due to mount race conditions runc: container escape with malicious config due to /dev/console mount and related races&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2025:21221</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21036-1 — Security update for runc</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21036-1</link>
      <description>&lt;p&gt;Security update for runc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for runc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21036-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-31133</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-31133</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: runc, Ubuntu:Pro:18.04:LTS: runc, Ubuntu:20.04:LTS: runc, Ubuntu:20.04:LTS: runc-app, Ubuntu:22.04:LTS: runc, Ubuntu:22.04:LTS: runc-app, Ubuntu:24.04:LTS: runc, Ubuntu:24.04:LTS: runc-app, Ubuntu:25.10: runc, Ubuntu:25.10: runc-app and 1 more&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container&amp;#39;s /dev/null) was actually a real /dev/null inode when using the container&amp;#39;s /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: runc, Ubuntu:Pro:18.04:LTS: runc, Ubuntu:20.04:LTS: runc, Ubuntu:20.04:LTS: runc-app, Ubuntu:22.04:LTS: runc, Ubuntu:22.04:LTS: runc-app, Ubuntu:24.04:LTS: runc, Ubuntu:24.04:LTS: runc-app, Ubuntu:25.10: runc, Ubuntu:25.10: runc-app and 1 more&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container&amp;#39;s /dev/null) was actually a real /dev/null inode when using the container&amp;#39;s /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-31133</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2518 — Red Hat Enterprise Linux (runc): Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2518</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Red Hat OpenShift ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Red Hat OpenShift ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2518</guid>
    </item>
  </channel>
</rss>
