Логотип exploitDog
bind:CVE-2025-31133
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-31133

Количество 9

Количество 9

ubuntu логотип

CVE-2025-31133

8 дней назад

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack: an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.

EPSS: Низкий
nvd логотип

CVE-2025-31133

8 дней назад

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack: an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.

EPSS: Низкий
msrc логотип

CVE-2025-31133

6 дней назад

runc container escape via "masked path" abuse due to mount race conditions

EPSS: Низкий
debian логотип

CVE-2025-31133

8 дней назад

runc is a CLI tool for spawning and running containers according to th ...

EPSS: Низкий
github логотип

GHSA-9493-h29p-rfm2

9 дней назад

runc container escape via "masked path" abuse due to mount race conditions

EPSS: Низкий
fstec логотип

BDU:2025-14041

10 дней назад

Уязвимость функции maskedPaths инструмента для запуска изолированных контейнеров runc, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 8.2
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3951-1

9 дней назад

Security update for runc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3950-1

9 дней назад

Security update for runc

EPSS: Низкий
oracle-oval логотип

ELSA-2025-19927

8 дней назад

ELSA-2025-19927: runc security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-31133

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack: an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.

0%
Низкий
8 дней назад
nvd логотип
CVE-2025-31133

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack: an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.

0%
Низкий
8 дней назад
msrc логотип
CVE-2025-31133

runc container escape via "masked path" abuse due to mount race conditions

0%
Низкий
6 дней назад
debian логотип
CVE-2025-31133

runc is a CLI tool for spawning and running containers according to th ...

0%
Низкий
8 дней назад
github логотип
GHSA-9493-h29p-rfm2

runc container escape via "masked path" abuse due to mount race conditions

0%
Низкий
9 дней назад
fstec логотип
BDU:2025-14041

Уязвимость функции maskedPaths инструмента для запуска изолированных контейнеров runc, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 8.2
0%
Низкий
10 дней назад
suse-cvrf логотип
SUSE-SU-2025:3951-1

Security update for runc

9 дней назад
suse-cvrf логотип
SUSE-SU-2025:3950-1

Security update for runc

9 дней назад
oracle-oval логотип
ELSA-2025-19927

ELSA-2025-19927: runc security update (IMPORTANT)

8 дней назад

Уязвимостей на страницу