VDB
GO-2025-4096
GO-2025-4096
PUBLISHED
Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | opencontainers/runc | 1.3.0-rc.1, 1.4.0-rc.1, 0 |
Timeline
- Nov 18, 2025 CVE Published
- Feb 4, 2026 CVE Updated
References
- https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2 advisory
- https://github.com/opencontainers/runc/commit/1a30a8f3d921acbbb6a4bb7e99da2c05f8d48522 patch
- https://github.com/opencontainers/runc/commit/5d7b2424072449872d1cd0c937f2ca25f418eb66 patch
- https://github.com/opencontainers/runc/commit/8476df83b534a2522b878c0507b3491def48db9f patch
- https://github.com/opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64 patch