Threat actors using malicious container images or Dockerfiles could harness a trio of new vulnerabilities in the runC container runtime to escape Docker and Kubernetes containers, according to BleepingComputer.Exploiting both CVE-2025-31133 and CVE-2025-52565 allows container breakouts through writable access to /proc and procfs entries, respectively, while abuse of CVE-2025-52881 enables the circumvention of LSM relabel protections, transforming traditional runc writes into arbitrary writes, with Sysdig researchers emphasizing the need for containers with custom mount configurations to harness the security issues.Despite the lack of active exploitation, organizations leveraging vulnerable runC versions have been advised to promptly implement updated iterations to prevent potential compromise. Organizations were also urged by runC developers to enable user namespaces across all containers to curb the threat. Attacks leveraging the flaws could also be determined through the tracking of dubious symlink behaviors, said Sysdig researchers, who also promoted rootless container usage.
Vulnerability Management, Cloud Security
Docker, Kubernetes container escape possible with runC vulnerabilities

(sharafmaksumov/stock.adobe.com)
An In-Depth Guide to Cloud Security
Get essential knowledge and practical strategies to fortify your cloud security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



