Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-19927

Опубликовано: 07 нояб. 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-19927: runc security update (IMPORTANT)

[4:1.2.5-3]

  • Add relevant patches to CVEs
  • Resolves: RHEL-122402

[4:1.2.5-2]

  • fix CVE-2025-31133 CVE-2025-52565 CVE-2025-52881
  • Resolves: RHEL-122402
  • Resolves: RHEL-122404
  • Resolves: RHEL-122415

[4:1.2.5-1]

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

runc

1.2.5-3.el9_6

Oracle Linux x86_64

runc

1.2.5-3.el9_6

Связанные уязвимости

suse-cvrf
9 дней назад

Security update for runc

suse-cvrf
9 дней назад

Security update for runc

ubuntu
8 дней назад

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack: an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.

nvd
8 дней назад

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack: an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.

msrc
6 дней назад

runc container escape via "masked path" abuse due to mount race conditions