VDB

DEBIAN-CVE-2025-31133

DEBIAN-CVE-2025-31133 PUBLISHED CVSS 7.800000190734863 HIGH

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack: an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:13runc1.3.3+ds1-2, 1.3.3+ds1-3, 1.3.5+ds1-1
Debian:12runc1.1.5+ds1-1, 1.1.5+ds1-1+deb12u1, 1.1.5+ds1-2
Debian:11runc*, 1.1.5+ds1, 1.1.5+ds1
Debian:14runc*, *, 1.3.3+ds1

Timeline

  • Nov 6, 2025 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›