CVE-2025-31133

Aliases:GHSA-9493-h29p-rfm2GO-2025-4096DEBIAN-CVE-2025-31133CGA-2662-qv7j-89xcCGA-2v25-pcf2-5vh3CGA-2xh8-68xf-x8c9CGA-4c76-26xj-pvphCGA-4c8m-4rxh-qv3cCGA-4h26-x7wp-vvrxCGA-4mp5-gvcg-fwrjCGA-5mj5-73c7-r42xCGA-5phj-5fp8-v2q7CGA-6hgp-hf56-x89cCGA-74gq-hmj5-v55pCGA-7hmq-56jj-jhwwCGA-83w3-xwhq-gcpxCGA-897p-j7hf-h496CGA-8q62-hqr2-6w74CGA-94ff-2xjq-5v5hCGA-f7gx-cghh-rghxCGA-ff36-jmjm-jx56CGA-gx74-5224-4qrmCGA-h3h7-mhw8-ch3rCGA-h7gc-wh28-mmv4CGA-hq2x-fvw2-8crqCGA-hwwq-4wwg-4g63CGA-jgxv-rxh5-36mhCGA-m3jg-2x93-vw7fCGA-m4c7-q5qm-q7w9CGA-m8rr-pj2f-7864CGA-24gp-39vp-p765CGA-28hv-2pjp-7h93CGA-28xj-v2jc-xq9hCGA-2g76-8wcc-fmvpCGA-2j2p-874w-2627CGA-2j7q-rjr3-cc77CGA-2j9q-8m86-7p25CGA-2mmq-p2w4-xprhCGA-2pvg-pv8m-pfg6CGA-2q72-77vc-68wjCGA-2wrr-g3xw-8m8xCGA-348x-9wgr-cpf4CGA-35ww-8mh8-p6mfCGA-38fc-f5q4-fjggCGA-39qm-q6h7-r5gwCGA-39wf-7p37-q5mcCGA-3h2r-wx93-v3xjCGA-3hg4-gmcc-4c79CGA-3q4c-3jwg-3pm7CGA-3qm6-pfhc-wqfpCGA-3vf7-vqpc-674xCGA-3vm5-q9w2-h9qqCGA-44xc-39jh-65v3CGA-45g7-2244-2r94CGA-465m-j7pg-w8vmCGA-472c-mwxr-39r6CGA-4757-f5f5-7gjwCGA-47gw-9h9f-2xpwCGA-4mpp-8gf4-f9jpCGA-4phq-p8wx-9525CGA-4phx-4xc2-vfw8CGA-4vfr-599x-gcq7CGA-4vpx-j2mp-gmhvCGA-4xf8-jc53-87mvCGA-539v-w9hm-jh39CGA-53fh-p9qw-pvvvCGA-56qj-8vxr-77vgCGA-5784-qrmr-xm59CGA-57wf-296q-xvpqCGA-58g3-mp58-2rr3CGA-5cj6-74p4-xvgwCGA-5gxw-c6h6-7qpvCGA-5vpv-hwwf-chwjCGA-5wq7-jmqv-j3rpCGA-5xc4-cj9q-v5q8CGA-628m-h88r-m749CGA-654v-7w6v-jfp5CGA-658w-hcgx-r8q4CGA-65wx-vwc9-5fg5CGA-66gj-pj7c-mvw6CGA-67xx-p367-x674CGA-68hw-94hq-5rg2CGA-6c2x-wx2r-r9c2CGA-6c6q-qvf7-g83hCGA-6chj-4p6x-g8m6CGA-6f6c-hjj7-w2mwCGA-6g2q-5896-g6vgCGA-6r97-9cmj-46jfCGA-6x8c-36xh-jp3pCGA-72vh-vf7r-qjpfCGA-74xm-jxv5-4xc6CGA-77mh-vw4r-vrpgCGA-78g8-rh68-39jjCGA-7ghm-fgv8-228jCGA-7hpj-c8j8-jwvxCGA-7jrf-57cw-79mpCGA-7m4v-653w-76w3CGA-7m84-rw8j-xh67CGA-7p8h-f697-56wpCGA-7pq2-xrrj-6cfpCGA-7vmm-ccpf-9c8gCGA-7xm6-3gvr-h28hCGA-848c-f29j-mj6fCGA-855w-8g5q-8xvjCGA-858f-922p-7rp6CGA-8hvr-p2gg-8pvcCGA-8jp7-6q6w-7jvpCGA-8jxj-277v-38w6CGA-92h8-fx52-qh6vCGA-956c-9rmf-w523CGA-98gf-45fj-j43vCGA-9f86-gph4-mmwcCGA-9mj8-x3m5-mf9mCGA-9p5x-wv4p-v8qwCGA-9rh8-p6rv-gfw9CGA-c2hp-769g-3qfrCGA-c2j6-c64r-gm6hCGA-c3pg-84rj-8w62CGA-c3q4-9r9f-q247CGA-c3x9-76cj-gmqrCGA-c4j2-w6h3-qq87CGA-c66r-cjfj-2vrqCGA-c8p9-gwm3-vgjvCGA-c9ff-72r8-65h6CGA-c9pp-2qrv-w5fwCGA-c9x6-x868-5x8pCGA-cf3w-fjww-24v3CGA-cjfx-g5m3-x59hCGA-f3fr-5x4h-99h8CGA-f3vj-66pw-7jq3CGA-f4fp-x6px-6h73CGA-f5m2-8h36-h784CGA-f9vp-45x7-rp7gCGA-ffmc-f7pw-r2g6CGA-fgg8-9vqq-779cCGA-fgph-gjp4-qph5CGA-fwvv-3r65-9mcrCGA-g698-mjpw-vjcjCGA-g7hq-w379-46g9CGA-gc9m-rfpm-v683CGA-gcmw-7p4c-ggmmCGA-gcwg-q9rx-vg4qCGA-gf72-rwc5-4446CGA-gj86-34v9-v5c2CGA-gj97-m3wx-f4x6CGA-gmh9-7753-gxxhCGA-gqp4-q2gg-jx7xCGA-gv6p-275g-q3v2CGA-gxmm-ggxx-crccCGA-h664-vxhh-vxqxCGA-hp9w-w55v-973xCGA-hq8r-96w6-hc9pCGA-hrvm-6622-ghq3CGA-hvxf-v9vf-wvvqCGA-j25f-v8cf-43cgCGA-j3gp-rrfq-pj6cCGA-j3q8-q9gc-p9c8CGA-j5jx-q8x6-vm3wCGA-j7mh-hq82-q8jxCGA-jqrf-wrw8-xj8mCGA-jrw8-qj6g-v3qgCGA-m5rr-7785-3qh5CGA-m66r-g37q-7x4cCGA-m7xf-rgv2-mm2wCGA-m8mp-46vq-2vqqCGA-mc4q-9hc8-vgvrCGA-mg4m-5g5m-xxhhCGA-mhx3-c357-qqfcCGA-mr2g-w687-wg9vCGA-mv55-4rfp-h5rwCGA-mv92-fcc9-73mcCGA-mx8m-3836-73q4CGA-p224-gpg9-5hmfCGA-p56h-5x74-m2c8CGA-pghj-xgmq-prr4CGA-pgmv-465v-wpq4CGA-pj2h-p6q7-566rCGA-pppv-7f48-2j27CGA-prrw-cjh7-2pvgCGA-pvf5-cg6g-rcgwCGA-q2cx-4q59-79rxCGA-q2m6-75pc-g7qjCGA-q4gq-g3hj-vphgCGA-q536-h264-2p3qCGA-q652-p28p-c8hgCGA-q87f-wjfj-25vqCGA-q9wh-v5wv-w645CGA-qg5m-jm8g-mfw5CGA-qjxg-6pcq-h5h2CGA-qqf8-mqc3-vjghCGA-qr34-hhj6-m9rmCGA-qr8r-g39m-fjpwCGA-qr94-fp56-r22xCGA-qv8p-wh8w-qmm8CGA-r7g2-mhwm-4vp4CGA-r862-m68g-4jcmCGA-r9c6-g2g4-xj4cCGA-r9h5-qm8c-h3mvCGA-r9x7-82c3-q82pCGA-rc4x-jr68-qhf2CGA-rcgg-w239-6cc2CGA-rj2m-44mv-3w97CGA-rm29-wrpg-qgwrCGA-rrmj-w5rc-7xp4CGA-rw47-7fgq-gmmqCGA-rwvq-rxh3-966gCGA-rxfm-2v6w-fc28CGA-v34j-4pgp-j96pCGA-v43m-92vg-p565CGA-v5wp-h5xr-jqm7CGA-v7h5-qmwq-wqwwCGA-v7qw-9q9c-25gfCGA-vfqx-4m86-w3cxCGA-vgw7-wh3h-jgvvCGA-vhpf-v8xc-f662CGA-vp7h-2hwr-v27pCGA-vphc-42qx-64wfCGA-vprr-vjmq-h22qCGA-vrcc-x4gf-595pCGA-vrf6-f4vr-7599CGA-vrwg-2pc3-pr5pCGA-vww3-c5hg-jcp7CGA-vx8p-x7hp-3w7pCGA-w4w5-83qr-xrm9CGA-w62g-vrc8-h73wCGA-wcjm-9v9f-fqpjCGA-wf98-jqcf-v797CGA-wg6p-3rp9-5j37CGA-wr5p-j42v-6cvxCGA-wv5v-hvpx-8mqwCGA-wwxv-293p-9pf4CGA-x22j-gqx5-fwqwCGA-x42h-g5mp-53mjCGA-x555-247j-qwj4CGA-x672-xqgv-6vf5CGA-x795-249m-wvf8CGA-xcgc-4fp2-m462CGA-xhmf-7959-p7h4CGA-xphm-2xwh-hgrxCGA-xrqf-c9j3-93r6CGA-xv6x-4m8x-m4xgCGA-xvqg-rhwx-2cc2CGA-xwmw-6xw2-8wpmCGA-xx58-w28f-qg6gCGA-3gf5-79wr-jx52CGA-53cm-5qmw-2cprCGA-58vq-mqc6-5q38CGA-78qr-9cgj-26xhCGA-7qgg-fgc8-p3vhCGA-gj5m-wm4h-rr5jCGA-hm6w-xcrp-w6mgCGA-77rv-9wwx-6r8v
Analyzed
Published: 06 Nov 2025, 18:47
Last modified:06 Nov 2025, 19:22

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.84% LOW
1% probability +0.82%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Nov 2025, 18:47
Published
Vulnerability first disclosed
06 Nov 2025, 19:22
Last Modified
Vulnerability information updated

Description

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack: an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.

CVSS Metrics

  • v4.0HIGHScore: 7.3CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
  • v4.0HIGHScore: 7.3CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.84% Percentile: 56%

Techniques & Countermeasures

  • CWE-61UNIX Symbolic Link (Symlink) Following

    The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

  • CWE-363Race Condition Enabling Link Following

    The product checks the status of a file or directory before accessing it, which produces a race condition in which the file can be replaced with a link before the access is performed, causing the product to access the wrong file.

Affected Systems

  • chainguardazure-vnet-cni

    < 1.7.4-r2

  • chainguardbuildah

    < 1.42.0-r1

  • chainguardcluster-autoscaler-1.31

    < 1.31.5-r4 | < 1.31.5-r1

  • chainguardcluster-autoscaler-fips-1.31

    < 1.31.5-r1 | < 1.31.5-r5

  • chainguardctop

    all

  • chainguardctop-fips

    all

  • chainguardeks-distro-1.30

    < 1.30.46-r1

  • chainguardeks-distro-1.31

    < 1.31.35-r1

  • chainguardeks-distro-1.32

    < 1.32.28-r1

  • chainguardeks-distro-coredns-1.30

    < 1.30.46-r1

  • chainguardeks-distro-coredns-1.31

    < 1.31.35-r1

  • chainguardeks-distro-coredns-1.32

    < 1.32.28-r1

  • chainguardeks-distro-coredns-fips-1.29

    < 1.29.53-r1

  • chainguardeks-distro-coredns-fips-1.30

    < 1.30.46-r1

  • chainguardeks-distro-fips-1.29

    < 1.29.53-r1

  • chainguardeks-distro-fips-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-apiserver-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-apiserver-1.31

    < 1.31.35-r1

  • chainguardeks-distro-kube-apiserver-1.32

    < 1.32.28-r1

  • chainguardeks-distro-kube-apiserver-fips-1.29

    < 1.29.53-r1

  • chainguardeks-distro-kube-apiserver-fips-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-controller-manager-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-controller-manager-1.31

    < 1.31.35-r1

  • chainguardeks-distro-kube-controller-manager-1.32

    < 1.32.28-r1

  • chainguardeks-distro-kube-controller-manager-fips-1.29

    < 1.29.53-r1

  • chainguardeks-distro-kube-controller-manager-fips-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-controller-manager-fips-1.32

    < 1.32.28-r1

  • chainguardeks-distro-kube-proxy-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-proxy-1.31

    < 1.31.35-r1

  • chainguardeks-distro-kube-proxy-fips-1.29

    < 1.29.53-r1

  • chainguardeks-distro-kube-proxy-fips-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-proxy-fips-1.32

    < 1.32.28-r1

  • chainguardeks-distro-kube-scheduler-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-scheduler-1.31

    < 1.31.35-r1

  • chainguardeks-distro-kube-scheduler-1.32

    < 1.32.28-r1

  • chainguardeks-distro-kube-scheduler-fips-1.29

    < 1.29.53-r1

  • chainguardeks-distro-kube-scheduler-fips-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kubernetes-pause-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kubernetes-pause-1.31

    < 1.31.35-r1

  • chainguardfalco-no-driver

    < 0.43.0-r0

  • chainguardgosu-1.11

    all

  • chainguardgrafana-alloy

    < 1.11.3-r1

  • chainguardgrafana-alloy-fips

    < 1.11.3-r2

  • chainguardharvester-fips

    < 0

  • chainguardharvester-fips-upgrade-helper

    < 0

  • chainguardharvester-fips-webhook

    < 0

  • chainguardharvester-upgrade-helper

    < 0

  • chainguardk3s-1.32

    < 1.32.9.1-r2

  • chainguardk3s-1.33

    < 1.33.5.1-r2

  • chainguardk3s-multicall-1.32

    < 1.32.9.1-r2

Showing first 50 affected entries in server-rendered view.

References (9)