CVE-2025-52881CWE-363CWE-61

runc: LSM labels can be bypassed with malicious config using dummy procfs files

High · published November 6, 2025

CVSS v4.0
7.3
EPSS
1%
Percentile
44.8
In the wild
Unconfirmed
What it is

⚡ An attacker can trick runc into misdirecting writes through some sneaky container racing! 🚀 Think of it like a busy restaurant kitchen where orders are getting mixed up — when containers race to the same task, one might accidentally serve the wrong dish to a customer because they got distracted by a shared counter. 🍽️ This flaw could allow an attacker to manipulate important files in the proc filesystem, potentially leading to unauthorized access or changes to sensitive information. If exploited, it could be a gateway to a host of other attacks, putting your system at serious risk! 🔥

Put simply

Think of it like a busy restaurant kitchen where orders are getting mixed up — when containers race to the same task, one might accidentally serve the wrong dish to a customer because they got distracted by a shared counter. 🍽️ In runc versions 1.2.7, 1.3.2, and 1.4.0-rc.2, attackers can exploit a race condition in container execution with shared mounts, redirecting writes to unintended procfs files. This vulnerability can be triggered by using symbolic links or bind mounts in racing containers.

What to do

This flaw could allow an attacker to manipulate important files in the proc filesystem, potentially leading to unauthorized access or changes to sensitive information. If exploited, it could be a gateway to a host of other attacks, putting your system at serious risk! 🔥 Upgrade runc to versions 1.2.8, 1.3.3, or 1.4.0-rc.3 to mitigate this issue. Additionally, ensure your container configurations are reviewed for shared mount security. Don't forget to check for any other dependencies that might be affected! 🛡️ You've got this! Follow these steps, and you'll be strengthening your defenses in no time! 💪✨

The record
Technical detail
CVSS v4.0
7.3 · HIGH
Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS
0.00564 · 44.8th percentile
Weaknesses
CWE-363 · Race Condition Enabling Link Following; CWE-61 · UNIX Symbolic Link (Symlink) Following
Published
2025-11-06T20:23Z
EPSS history
Timeline
  • 06 NOV 20:23Z
    runc: LSM labels can be bypassed with malicious config using dummy procfs files
    cvelistv5