CVE Database
/

CVE-2025-31133

Back to search

CVE-2025-31133

Published: Nov 6, 2025

Modified: Nov 6, 2025

PUBLISHED

Description

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack: an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.

VendorProductVersions

opencontainers

runc

affected
< 1.2.8
affected
>= 1.3.0-rc.1, < 1.3.3
affected
>= 1.4.0-rc.1, <= 1.4.0-rc.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now