<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:46:04 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:19927 — Important: runc security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:19927</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: runc&lt;/p&gt;
&lt;p&gt;The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* runc: container escape via &amp;#39;masked path&amp;#39; abuse due to mount race conditions (CVE-2025-31133)
  * runc: container escape with malicious config due to /dev/console mount and related races (CVE-2025-52565)
  * runc: container escape and denial of service due to arbitrary write gadgets and procfs write redirects (CVE-2025-52881)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: runc&lt;/p&gt;
&lt;p&gt;The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* runc: container escape via &amp;#39;masked path&amp;#39; abuse due to mount race conditions (CVE-2025-31133)
  * runc: container escape with malicious config due to /dev/console mount and related races (CVE-2025-52565)
  * runc: container escape and denial of service due to arbitrary write gadgets and procfs write redirects (CVE-2025-52881)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:19927</guid>
    </item>
    <item>
      <title>bdu:2025-14040</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14040</link>
      <description>bdu:2025-14040</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14040</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-52881</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-52881</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: buildah, Alpaquita:23: podman, Alpaquita:23: runc, Alpaquita:25: buildah, Alpaquita:25: podman, Alpaquita:25: runc, Alpaquita:stream: buildah, Alpaquita:stream: podman, Alpaquita:stream: runc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: buildah, Alpaquita:23: podman, Alpaquita:23: runc, Alpaquita:25: buildah, Alpaquita:25: podman, Alpaquita:25: runc, Alpaquita:stream: buildah, Alpaquita:stream: podman, Alpaquita:stream: runc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-52881</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1036 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1036</link>
      <description>certfr-2025-avi-1036</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1036</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BY81163 — Security fixes in local-static-provisioner-fips 2.6.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-by81163</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: local-static-provisioner-fips&lt;/p&gt;
&lt;p&gt;Package local-static-provisioner-fips version 2.6.0-r1 fixes 6 vulnerabilities: CVE-2023-44487, ghsa-m425-mq94-257g, CVE-2024-24786, ghsa-8r3f-844c-mc37, CVE-2025-52881...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: local-static-provisioner-fips&lt;/p&gt;
&lt;p&gt;Package local-static-provisioner-fips version 2.6.0-r1 fixes 6 vulnerabilities: CVE-2023-44487, ghsa-m425-mq94-257g, CVE-2024-24786, ghsa-8r3f-844c-mc37, CVE-2025-52881...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-by81163</guid>
    </item>
    <item>
      <title>EUVD-2026-260262</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260262</link>
      <description>EUVD-2026-260262</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260262</guid>
    </item>
    <item>
      <title>fkie_cve-2025-52881</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52881</link>
      <description>&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-52881</guid>
    </item>
    <item>
      <title>GHSA-cgrx-mc8f-2prm — runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cgrx-mc8f-2prm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/opencontainers/runc, Go: github.com/opencontainers/selinux&lt;/p&gt;
&lt;p&gt;### Impact ###&lt;/p&gt;
&lt;p&gt;This attack is primarily a more sophisticated version of CVE-2019-19921, which was a flaw which allowed an attacker to trick runc into writing the LSM process labels for a container process into a dummy `tmpfs` file and thus not apply the correct LSM labels to the container process. The mitigation runc applied for CVE-2019-19921 was fairly limited and effectively only caused runc to verify that when runc writes LSM labels that those labels are actual procfs files.&lt;/p&gt;
&lt;p&gt;Rather than using a fake `tmpfs` file for `/proc/self/attr/&amp;lt;label&amp;gt;`, an attacker could instead (through various means) make `/proc/self/attr/&amp;lt;label&amp;gt;` reference a real `procfs` file, but one that would still be a no-op (such as `/proc/self/sched`). This would have the same effect but would clear the &amp;#34;is a procfs file&amp;#34; check. Runc is aware that this kind of attack would be possible (even going so far as to discuss this publicly as &amp;#34;future work&amp;#34; at conferences), and runc is working on a far more comprehensive mitigation of this attack, but this security issue was disclosed before runc could complete this work.&lt;/p&gt;
&lt;p&gt;In all known versions of runc, an attacker can trick runc into misdirecting writes to `/proc` to other procfs files through the use of a racing container with shared mounts (runc has also verified this attack is possible to exploit using a standard Dockerfile with `docker buildx build` as that also permits triggering parallel execution of containers with custom shared mounts configured). This r…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/opencontainers/runc, Go: github.com/opencontainers/selinux&lt;/p&gt;
&lt;p&gt;### Impact ###&lt;/p&gt;
&lt;p&gt;This attack is primarily a more sophisticated version of CVE-2019-19921, which was a flaw which allowed an attacker to trick runc into writing the LSM process labels for a container process into a dummy `tmpfs` file and thus not apply the correct LSM labels to the container process. The mitigation runc applied for CVE-2019-19921 was fairly limited and effectively only caused runc to verify that when runc writes LSM labels that those labels are actual procfs files.&lt;/p&gt;
&lt;p&gt;Rather than using a fake `tmpfs` file for `/proc/self/attr/&amp;lt;label&amp;gt;`, an attacker could instead (through various means) make `/proc/self/attr/&amp;lt;label&amp;gt;` reference a real `procfs` file, but one that would still be a no-op (such as `/proc/self/sched`). This would have the same effect but would clear the &amp;#34;is a procfs file&amp;#34; check. Runc is aware that this kind of attack would be possible (even going so far as to discuss this publicly as &amp;#34;future work&amp;#34; at conferences), and runc is working on a far more comprehensive mitigation of this attack, but this security issue was disclosed before runc could complete this work.&lt;/p&gt;
&lt;p&gt;In all known versions of runc, an attacker can trick runc into misdirecting writes to `/proc` to other procfs files through the use of a racing container with shared mounts (runc has also verified this attack is possible to exploit using a standard Dockerfile with `docker buildx build` as that also permits triggering parallel execution of containers with custom shared mounts configured). This r…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cgrx-mc8f-2prm</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-52881 — runc: LSM labels can be bypassed with malicious config using dummy procfs files</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-52881</link>
      <description>msrc_CVE-2025-52881</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-52881</guid>
    </item>
    <item>
      <title>OESA-2025-2820 — runc security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2820</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: runc, openEuler:22.03-LTS-SP3: runc, openEuler:22.03-LTS-SP4: runc, openEuler:24.03-LTS: runc, openEuler:24.03-LTS-SP1: runc, openEuler:24.03-LTS-SP2: runc&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container&amp;amp;apos;s /dev/null) was actually a real /dev/null inode when using the container&amp;amp;apos;s /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.(CVE-2025-31133)&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of `/dev/pts/$n` to `/dev/console` as configured for all containers that allocate a console). This happens after `pivot_root(2)`, so this cannot…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: runc, openEuler:22.03-LTS-SP3: runc, openEuler:22.03-LTS-SP4: runc, openEuler:24.03-LTS: runc, openEuler:24.03-LTS-SP1: runc, openEuler:24.03-LTS-SP2: runc&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container&amp;amp;apos;s /dev/null) was actually a real /dev/null inode when using the container&amp;amp;apos;s /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.(CVE-2025-31133)&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of `/dev/pts/$n` to `/dev/console` as configured for all containers that allocate a console). This happens after `pivot_root(2)`, so this cannot…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2820</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15705-1 — runc-1.3.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15705-1</link>
      <description>&lt;p&gt;runc-1.3.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;runc-1.3.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15705-1</guid>
    </item>
    <item>
      <title>RHBA-2025:21224 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.20.4 bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2025:21224</link>
      <description>&lt;p&gt;runc: container escape via &amp;#39;masked path&amp;#39; abuse due to mount race conditions runc: container escape with malicious config due to /dev/console mount and related races runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;runc: container escape via &amp;#39;masked path&amp;#39; abuse due to mount race conditions runc: container escape with malicious config due to /dev/console mount and related races runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2025:21224</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21036-1 — Security update for runc</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21036-1</link>
      <description>&lt;p&gt;Security update for runc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for runc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21036-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-52881</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-52881</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: runc, Ubuntu:Pro:18.04:LTS: runc, Ubuntu:20.04:LTS: runc, Ubuntu:20.04:LTS: runc-app, Ubuntu:22.04:LTS: runc, Ubuntu:22.04:LTS: runc-app, Ubuntu:24.04:LTS: runc, Ubuntu:24.04:LTS: runc-app, Ubuntu:25.10: runc, Ubuntu:25.10: runc-app and 1 more&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: runc, Ubuntu:Pro:18.04:LTS: runc, Ubuntu:20.04:LTS: runc, Ubuntu:20.04:LTS: runc-app, Ubuntu:22.04:LTS: runc, Ubuntu:22.04:LTS: runc-app, Ubuntu:24.04:LTS: runc, Ubuntu:24.04:LTS: runc-app, Ubuntu:25.10: runc, Ubuntu:25.10: runc-app and 1 more&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-52881</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2518 — Red Hat Enterprise Linux (runc): Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2518</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Red Hat OpenShift ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Red Hat OpenShift ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2518</guid>
    </item>
  </channel>
</rss>
