runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.
CVE-2025-52881
This high-severity CVE scores 7.5 under NVD CVSS v3. EPSS exploit probability: 0.6% (45th percentile of EPSS-scored CVEs). GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
A fix is available — apply it.
- CVSS v3
- 7.5
- EG Score
- 7.5HIGHmedium confidence
- EG Risk
- 50EG Risk 50/100CISA SSVC
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity75% × 45%Exploitation40% × 40%Automatability0% × 15%CISA SSVC: Track at low or medium mission impact; Track* at high (mission-essential systems).Action: A fix is available. Apply it within your standard update timelines. - EPSS PROB
- 0.6%
- EPSS %ILE
- 45th
- KEV
- Not listed
CISA SSVCTrack at low or medium mission impact; Track* at high (mission-essential systems).
A fix is available. Apply it within your standard update timelines.
Exploitation none (CISA Vulnrichment) · Automatable no (CISA Vulnrichment) · Technical impact total (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table
Published
November 6, 2025
Last Modified
October 7, 2026
Advisory Details (10)
Auto-updated Oct 7, 2026commit 77d217c7c377 (opencontainers/runc)
Fix landed in opencontainers/runc commit 77d217c7c377 — awaiting tagged release
https://github.com/opencontainers/runc/commit/77d217c7c3775d8ca5af89e477e81568ef4572dbcommit 77889b56db93 (opencontainers/runc)
Fix landed in opencontainers/runc commit 77889b56db93 — awaiting tagged release
https://github.com/opencontainers/runc/commit/77889b56db939c323d29d1130f28f9aea2edb544commit 6fc191449109 (opencontainers/runc)
Fix landed in opencontainers/runc commit 6fc191449109 — awaiting tagged release
https://github.com/opencontainers/runc/commit/6fc191449109ea14bb7d61238f24a33fe08c651fcommit 4b37cd93f86e (opencontainers/runc)
Fix landed in opencontainers/runc commit 4b37cd93f86e — awaiting tagged release
https://github.com/opencontainers/runc/commit/4b37cd93f86e72feac866442988b549b5b7bf3e6commit 44a0fcf685db (opencontainers/runc)
Fix landed in opencontainers/runc commit 44a0fcf685db — awaiting tagged release
https://github.com/opencontainers/runc/commit/44a0fcf685db051c80b8c269812bb177f5802c58commit 435cc81be6b7 (opencontainers/runc)
Fix landed in opencontainers/runc commit 435cc81be6b7 — awaiting tagged release
https://github.com/opencontainers/runc/commit/435cc81be6b79cdec73b4002c0dae549b2f6ae6dcommit 3f925525b44d (opencontainers/runc)
Fix landed in opencontainers/runc commit 3f925525b44d — awaiting tagged release
https://github.com/opencontainers/runc/commit/3f925525b44d247e390e529e772a0dc0c0bc3557runc/RELEASES.md at v1.4.0-rc.2 · opencontainers/runc · GitHub
https://github.com/opencontainers/runc/blob/v1.4.0-rc.2/RELEASES.mdcommit fdcc9d3cad2f (opencontainers/runc)
Fix landed in opencontainers/runc commit fdcc9d3cad2f — awaiting tagged release
http://github.com/opencontainers/runc/commit/fdcc9d3cad2f85954a241ccb910a61aaa1ef47f3commit a41366e74080 (opencontainers/runc)
Fix landed in opencontainers/runc commit a41366e74080 — awaiting tagged release
http://github.com/opencontainers/runc/commit/a41366e74080fa9f26a2cd3544e2801449697322Vendor Advisories for CVE-2025-52881(20)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2026:72851Red Hat Product SecurityHigh
Red Hat Security Advisory: multicluster engine for Kubernetes v2.9.8 security update
- RHSA-2026:61629Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (ROCm)
- RHSA-2026:61628Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat AI Inference Server Model Optimization Tools 3.2.2 (CUDA)
- RHSA-2026:61627Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (CUDA)
- RHSA-2026:41928Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Migration Toolkit for Containers
- RHSA-2026:39894Red Hat Product SecurityHigh
Red Hat Security Advisory: Release of containers for RHOSO 18.0.21
- RHSA-2026:37387Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.22.0 security, enhancement & bug fix update
- CVE-2025-52881Microsoft Security Response Center (MSRC)High
runc: LSM labels can be bypassed with malicious config using dummy procfs files
- +12 more
Patch Availability(30)
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(6 across 5 ecosystems)
Go(2)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| github.com/opencontainers/runc | — |
| — |
| github.com/opencontainers/selinux | — |
| — |
Debian:11(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| runc | 1.0.0+ds1-1 ... 1.3.5+ds1-1 (50 versions) |
| — |
Debian:12(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| runc | 1.1.10+ds1-1 ... 1.4.3+ds1-1 (26 versions) |
| — |
Debian:13(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| runc | 1.1.15+ds1-2 ... 1.4.3+ds1-1 (12 versions) |
| — |
Debian:14(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| runc | 1.1.15+ds1-2 ... 1.3.3+ds1-1 (7 versions) |
| — |
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(24)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
- Red HatRHBA-2025:21224IMPORTANT2025-11-05
RHBA-2025:21224 — Important
- Red HatRHSA-2025:19927IMPORTANT2025-11-05
RHSA-2025:19927 — Important
- Red HatRHSA-2025:20957IMPORTANT2025-11-05
RHSA-2025:20957 — Important
- Red HatRHSA-2025:21220IMPORTANT2025-11-05
RHSA-2025:21220 — Important
- Red HatRHSA-2025:21232IMPORTANT2025-11-05
RHSA-2025:21232 — Important
- Red HatRHSA-2025:21328IMPORTANT2025-11-05
RHSA-2025:21328 — Important
- Red HatRHSA-2025:21633IMPORTANT2025-11-05
RHSA-2025:21633 — Important
- Red HatRHSA-2025:21634IMPORTANT2025-11-05
RHSA-2025:21634 — Important
- Red HatRHSA-2025:21702IMPORTANT2025-11-05
RHSA-2025:21702 — Important
- Red HatRHSA-2025:21795IMPORTANT2025-11-05
RHSA-2025:21795 — Important
- Red HatRHSA-2025:21824IMPORTANT2025-11-05
RHSA-2025:21824 — Important
- Red HatRHSA-2025:22011IMPORTANT2025-11-05
RHSA-2025:22011 — Important
- Red HatRHSA-2025:22012IMPORTANT2025-11-05
RHSA-2025:22012 — Important
- Red HatRHSA-2025:22030IMPORTANT2025-11-05
RHSA-2025:22030 — Important
- Red HatRHSA-2025:22275IMPORTANT2025-11-05
RHSA-2025:22275 — Important
- Red HatRHSA-2025:23113IMPORTANT2025-11-05
RHSA-2025:23113 — Important
- Red HatRHSA-2025:23347IMPORTANT2025-11-05
RHSA-2025:23347 — Important
- Red HatRHSA-2025:23543IMPORTANT2025-11-05
RHSA-2025:23543 — Important
- Red HatRHSA-2026:0050IMPORTANT2025-11-05
RHSA-2026:0050 — Important
- Red HatRHSA-2026:0315IMPORTANT2025-11-05
RHSA-2026:0315 — Important
- Red HatRHSA-2026:0316IMPORTANT2025-11-05
RHSA-2026:0316 — Important
- Red HatRHSA-2026:0331IMPORTANT2025-11-05
RHSA-2026:0331 — Important
- Red HatRHSA-2026:0418IMPORTANT2025-11-05
RHSA-2026:0418 — Important
- Red HatRHSA-2026:0424IMPORTANT2025-11-05
RHSA-2026:0424 — Important
Data Freshness Timeline
(refreshed 9× in last 7d / 34× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 175 total refreshes for this CVE.
- 2026-10-09 20:06 UTCEPSS rescore
- 2026-10-08 17:10 UTCEPSS rescore
- 2026-10-07 23:47 UTCEPSS rescore
- 2026-10-07 21:39 UTCEG score recompute
- 2026-10-07 21:39 UTCVendor advisory
- 2026-10-06 15:17 UTCEPSS rescore
- 2026-10-05 17:42 UTCEPSS rescore
- 2026-10-04 23:21 UTCEPSS rescore
- 2026-10-03 14:24 UTCEPSS rescore
- 2026-10-02 01:11 UTCOSV refresh
- 2026-10-01 19:49 UTCEPSS rescore
- 2026-10-01 19:49 UTCEPSS rescore
- 2026-09-30 15:02 UTCEPSS rescore
- 2026-09-28 13:50 UTCEPSS rescore
- 2026-09-26 15:58 UTCEPSS rescore
- 2026-09-26 15:58 UTCEPSS rescore
- 2026-09-26 00:25 UTCEPSS rescore
- 2026-09-24 14:02 UTCEPSS rescore
- 2026-09-23 13:47 UTCEPSS rescore
- 2026-09-21 21:06 UTCEPSS rescore
- 2026-09-20 20:15 UTCEPSS rescore
- 2026-09-20 20:15 UTCEPSS rescore
- 2026-09-19 15:42 UTCEPSS rescore
- 2026-09-18 19:27 UTCEPSS rescore
- 2026-09-18 19:27 UTCEPSS rescore
Show 75 moreShow fewer
- 2026-09-17 19:29 UTCEPSS rescore
- 2026-09-16 14:07 UTCEPSS rescore
- 2026-09-16 05:14 UTCEPSS rescore
- 2026-09-13 16:46 UTCEPSS rescore
- 2026-09-12 18:36 UTCOSV refresh
- 2026-09-12 15:00 UTCEPSS rescore
- 2026-09-11 14:52 UTCEPSS rescore
- 2026-09-11 09:36 UTCEPSS rescore
- 2026-09-10 09:34 UTCEPSS rescore
- 2026-09-08 21:59 UTCEPSS rescore
- 2026-09-07 16:00 UTCEPSS rescore
- 2026-09-06 13:47 UTCEPSS rescore
- 2026-09-05 15:28 UTCEPSS rescore
- 2026-09-04 05:06 UTCEPSS rescore
- 2026-09-02 14:11 UTCEPSS rescore
- 2026-09-01 13:53 UTCEPSS rescore
- 2026-09-01 04:38 UTCEPSS rescore
- 2026-08-30 19:16 UTCEPSS rescore
- 2026-08-30 01:21 UTCEPSS rescore
- 2026-08-28 21:40 UTCEPSS rescore
- 2026-08-27 14:24 UTCEPSS rescore
- 2026-08-26 14:45 UTCEPSS rescore
- 2026-08-25 13:48 UTCEPSS rescore
- 2026-08-24 23:44 UTCOSV refresh
- 2026-08-24 14:16 UTCEPSS rescore
- 2026-08-24 09:22 UTCEPSS rescore
- 2026-08-23 00:18 UTCEPSS rescore
- 2026-08-21 23:48 UTCEPSS rescore
- 2026-08-20 22:54 UTCEPSS rescore
- 2026-08-19 17:03 UTCEPSS rescore
- 2026-08-18 13:47 UTCEPSS rescore
- 2026-08-17 13:46 UTCEPSS rescore
- 2026-08-16 14:55 UTCEPSS rescore
- 2026-08-16 02:13 UTCEPSS rescore
- 2026-08-15 01:29 UTCEPSS rescore
- 2026-08-13 21:59 UTCEPSS rescore
- 2026-08-12 13:50 UTCEPSS rescore
- 2026-08-12 13:50 UTCEPSS rescore
- 2026-08-11 13:42 UTCEPSS rescore
- 2026-08-10 23:59 UTCEPSS rescore
- 2026-08-09 13:46 UTCEPSS rescore
- 2026-08-08 17:19 UTCOSV refresh
- 2026-08-08 16:36 UTCEPSS rescore
- 2026-08-07 16:26 UTCEPSS rescore
- 2026-08-06 13:46 UTCEPSS rescore
- 2026-08-05 19:16 UTCEPSS rescore
- 2026-08-04 15:09 UTCEPSS rescore
- 2026-08-04 15:09 UTCEPSS rescore
- 2026-08-04 10:37 UTCEPSS rescore
- 2026-08-03 10:35 UTCEPSS rescore
- 2026-08-02 02:26 UTCEPSS rescore
- 2026-08-01 04:15 UTCEPSS rescore
- 2026-07-30 16:27 UTCEPSS rescore
- 2026-07-30 01:30 UTCEPSS rescore
- 2026-07-28 15:35 UTCEPSS rescore
- 2026-07-26 14:54 UTCEPSS rescore
- 2026-07-25 14:17 UTCEPSS rescore
- 2026-07-24 14:17 UTCEPSS rescore
- 2026-07-23 15:41 UTCOSV refresh
- 2026-07-23 14:18 UTCEPSS rescore
- 2026-07-23 02:58 UTCEG score recompute
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-21 15:24 UTCEPSS rescore
- 2026-07-20 17:08 UTCEPSS rescore
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-19 02:28 UTCEPSS rescore
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-16 17:02 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 01:59 UTCEPSS rescore
- 2026-07-15 01:59 UTCEPSS rescore
- 2026-07-13 22:29 UTCEPSS rescore
Publicly available exploits
(1 reference)Working exploit code is in the public domain (1 GitHub PoC). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCjq6l43d1/proxmox-lxc-docker-fixFirst seen Nov 11, 2025
Workaround for CVE-2025-52881: Fixes Docker/Podman breakage in Proxmox LXC containers caused by AppArmor incompatibility with runc 1.2.7+. Universal wrapper for community-scripts with automatic AppArmor configuration.
Open source ↗
Related CVEs(same product + same vendor + same CWE)
Same product
10 shownGo:github.com/opencontainers/selinux · Debian:11:runc
Same vendor
10 shownredhat:RHBA-2025:21224 · redhat:RHSA-2025:19927 · redhat:RHSA-2026:0050
Frequently asked(5)
What is CVE-2025-52881?
When was CVE-2025-52881 disclosed?
Is CVE-2025-52881 actively exploited?
What is the CVSS score of CVE-2025-52881?
How do I remediate CVE-2025-52881?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2025-52881
Is Your Infrastructure Affected by CVE-2025-52881?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.