AWS-2025-024
CVE-2025-31133, CVE-2025-52565, CVE-2025-52881 - runc container issues
🔗 CVE IDs covered (3)
📋 Description
Bulletin ID: AWS-2025-024 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/11/5 8:45 PM PDT
CVE Identifiers: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881
AWS is aware of recently disclosed security issues affecting the runc component of several open source container management systems (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) when launching new containers. AWS does not consider containers a security boundary, and does not utilize containers to isolate customers from each other. There is no cross-customer risk from these issues. AWS customers that utilize containers to isolate workloads within their own self-managed environments are strongly encouraged to contact their operating system vendor for any updates or instructions necessary to mitigate any potential concerns arising from these issues.
With the exception of the AWS services listed below, no customer action is required to address this issue. As a best practice, AWS always recommends that you apply all security patches and software version updates.
Affected services:
Amazon Linux Bottlerocket Amazon Elastic Container Service (ECS) Amazon Elastic Kubernetes Service (EKS) AWS Elastic Beanstalk Finch AWS Deep Learning AMI AWS Batch Amazon SageMaker