VDB

RHSA-2025%3A21824

RHSA-2025%3A21824 PUBLISHED CVSS 8.199999809265137 HIGH

A flaw was found in runc. This flaw exploits an issue with how masked paths are implementedin runc. When masking files, runc will bind-mount the container's /dev/null inode on top of the file. However, if an attacker can replace /dev/null with a symlink to some other procfs file, runc will instead bind-mount the symlink target read-write.

Risk Scores

CVSS 3.1
8.199999809265137
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatrhcos-aarch64-416.94.202511191934-0 as a component of Red Hat OpenShift Container Platform 4.16416.94.202511191934-0, 416.94.202511191934-0, rhcos-aarch64-416.94.202511191934-0
Red Hatrhcos-x86_64-416.94.202511191934-0 as a component of Red Hat OpenShift Container Platform 4.16*, rhcos-x86_64-416.94.202511191934-0, rhcos-x86_64-416.94.202511191934-0
Red Hatrhcos-ppc64le-416.94.202511191934-0 as a component of Red Hat OpenShift Container Platform 4.16*, 416.94.202511191934-0, *
Red Hatrhcos-s390x-416.94.202511191934-0 as a component of Red Hat OpenShift Container Platform 4.16rhcos-s390x-416.94.202511191934-0, *, rhcos-s390x-416.94.202511191934-0
Red Hatrhcos-s390x-416.94.202511191934-0 as a component of Red Hat OpenShift Container Platform 4.16416.94.202511191934-0, rhcos-s390x-416.94.202511191934-0, rhcos-s390x-416.94.202511191934-0
Red Hatrhcos-ppc64le-416.94.202511191934-0 as a component of Red Hat OpenShift Container Platform 4.16*, rhcos-ppc64le-416.94.202511191934-0, *
Red Hatrhcos-aarch64-416.94.202511191934-0 as a component of Red Hat OpenShift Container Platform 4.16rhcos-aarch64-416.94.202511191934-0, rhcos-aarch64-416.94.202511191934-0, *
Red Hatrhcos-x86_64-416.94.202511191934-0 as a component of Red Hat OpenShift Container Platform 4.16rhcos-x86_64-416.94.202511191934-0, *, rhcos-x86_64-416.94.202511191934-0

Timeline

  • Nov 27, 2025 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Jun 16, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›