CVE-2025-52565

Aliases:GHSA-qw9x-cqr3-wc7rGO-2025-4097DEBIAN-CVE-2025-52565CGA-29hm-3g7q-fg99CGA-2mfx-c7w4-rr24CGA-38x3-2pqh-5rfhCGA-3jx4-r5gf-w9pvCGA-3wjf-hg8h-cr6fCGA-3x98-rrmc-gc79CGA-4rg8-g7p5-pwpgCGA-5vqc-mvhm-877mCGA-9pmx-jmxm-g3v2CGA-f9hq-654p-rmvwCGA-fhvg-f2hv-ffp9CGA-g34r-7r55-52vmCGA-g3wv-7x2v-34mhCGA-g6r6-5rcr-jrg3CGA-hqhm-wf6g-f3fmCGA-hvwj-h6j8-2h76CGA-jjgg-8cmx-88qxCGA-m583-jm8x-m895CGA-mfph-q529-rj4pCGA-p2cg-2jrv-cxwvCGA-p5f7-vw4h-vfq9CGA-pfxp-p4hp-f29cCGA-pgh7-c58f-g7ppCGA-pp64-wmj9-h95jCGA-prv2-qw56-3rv6CGA-236c-gr76-cwqxCGA-24vq-wq35-94g3CGA-25xq-8736-jvm3CGA-27c3-j35c-3g47CGA-27jj-cgxc-xmx6CGA-28mw-h5px-87ccCGA-29wj-7m77-q46hCGA-2f7j-q7wv-3m82CGA-2g6h-3326-p6vmCGA-2h3g-cgp9-qvx5CGA-2pc8-xv2w-vjv9CGA-2pjp-rprw-w7q7CGA-2qvw-2439-9cw4CGA-2r67-rg26-9p3xCGA-2rjw-v3xp-p584CGA-2xj9-cg4r-xmfhCGA-35h4-76qr-4r4cCGA-35v6-f88v-r3r3CGA-364g-54wg-cg5qCGA-36jw-x85h-wcvvCGA-3823-chg4-jpp8CGA-38x9-x954-6h2pCGA-39c8-f5m3-448qCGA-3ch8-ff4p-6r7pCGA-3gc5-59hc-667wCGA-3hrw-rqwx-98g6CGA-3m8f-fwq7-jxv5CGA-3p5v-j497-wcv8CGA-3qx5-frqx-jxfgCGA-3w4h-33p4-pw9xCGA-3x33-v73g-6f4vCGA-479f-5prc-r47rCGA-4825-3323-562wCGA-48g9-77p3-qmq9CGA-496v-v837-j5w6CGA-49g5-wrww-5375CGA-4c97-fgfx-xp59CGA-4cgj-cjhv-m963CGA-4cvx-wqqj-3mqqCGA-4fh7-49fc-p42jCGA-4mvv-hfr5-ggm2CGA-4pwf-5hm3-rq35CGA-4r6p-rjq2-47g4CGA-4x45-5qgm-4w96CGA-526g-8jc9-3vfcCGA-52j5-p3fv-4f79CGA-53x4-mrxr-9g23CGA-563w-2mcj-wvm5CGA-57q5-fpxh-9v63CGA-5c55-vj8x-w5cqCGA-5ccg-x289-q4cpCGA-5f23-2g94-4wf7CGA-5g4f-xfjv-wwc7CGA-5m26-xhcr-57rgCGA-5m9m-v7rc-x97fCGA-5mx2-mh79-rx4qCGA-5pc7-7q3p-qr84CGA-5pp2-xchr-q29fCGA-5rmf-8c2p-655mCGA-62qg-8ppr-3wq6CGA-666v-9jgh-624pCGA-6hc4-94cp-jgr4CGA-6m5f-7gw3-fmqcCGA-6x4p-m738-j6xhCGA-6x87-cjw4-376gCGA-78gm-rg57-m48hCGA-7c5h-9xjm-89cfCGA-7cvv-94xj-xrpvCGA-7ggm-hxxg-3cjvCGA-7gqx-wf9h-vc4qCGA-7mhx-h8q3-4hrcCGA-7qcc-f3g9-5gwrCGA-7r5m-hq2p-q382CGA-7rhv-h2ph-7xjrCGA-7x4x-93f6-32mhCGA-85r4-fv2r-m22rCGA-88pc-75hf-q3fcCGA-8932-6q38-7cx5CGA-89h4-wcg8-8w74CGA-8jfg-229m-gh98CGA-8rg5-2qh5-x7xgCGA-8rqw-qmv3-xmgqCGA-8wh8-wxfr-wj75CGA-8x8f-m24m-pw9pCGA-92fr-mw2c-j8h7CGA-933m-965q-7qj4CGA-937x-826m-9v7wCGA-93ff-c387-f8mvCGA-99q3-5qhq-3fr5CGA-9fhr-pp6c-gjjqCGA-9jrq-3qf2-vg4hCGA-9qfx-wh43-rh9gCGA-9r35-j938-7mvrCGA-9w39-p49x-wj66CGA-9wwf-mxfp-hg38CGA-c386-3366-px22CGA-c45r-rpjf-pcp3CGA-c549-v6g2-wvhpCGA-c639-hmcp-24c3CGA-cffc-v8f3-xg4xCGA-cj4r-9jp3-57frCGA-cj9h-mgfx-xxj2CGA-cj9x-j63x-vp98CGA-cm46-hp8r-78h6CGA-cmc8-9hf7-8x7mCGA-cp99-rgqj-vvw4CGA-cw3h-f7xg-58jjCGA-f562-7x95-r3jrCGA-f6xq-2gq8-4x36CGA-f6xq-r72q-vg3vCGA-f922-h657-94cvCGA-fh86-m633-x2mmCGA-fpfm-r332-5g3cCGA-fvxv-x93v-g3xcCGA-fxcw-f94g-2938CGA-g372-h989-9397CGA-g3x7-3ffj-68r9CGA-g744-x644-6xxrCGA-g92h-hfr4-x6gvCGA-gc9m-5376-w3j8CGA-gjm4-c37r-g2prCGA-gm76-x9jp-5cg7CGA-gww5-73x2-r77vCGA-h34c-vpp8-w32fCGA-h3vh-vh8w-5jr8CGA-hh65-wq59-hcc7CGA-hhrc-rfv6-6rrqCGA-hq6c-6vh5-fx8fCGA-hq7j-gpwv-v7x6CGA-hqgq-697w-877hCGA-hqm4-r8jq-8343CGA-j553-6r36-hf36CGA-j6mc-vg2j-5q4wCGA-jc7r-78cg-7gcmCGA-jgg2-pv72-rpcwCGA-jhm5-rfw7-6j9qCGA-jmfw-fc3w-fpp7CGA-jpwx-w9h7-54hqCGA-jxjq-26m9-567mCGA-m5wc-m89w-5cgvCGA-m835-58q9-xh2cCGA-m9v8-r99x-m4v5CGA-mc5c-9jmp-q9crCGA-mc9r-c6g8-q2mpCGA-mhvp-mgm4-78p4CGA-mjc2-hj3f-x8m7CGA-mr3p-cj26-pc7hCGA-mr47-9q9x-jmx2CGA-p2v6-7hpv-ppvcCGA-p3q3-9fwf-cmpjCGA-p5gx-r8pv-96g7CGA-p6gf-pc2r-wpffCGA-pmwm-v466-93c7CGA-prjr-jhv5-fr5qCGA-px7x-5vwj-qgh5CGA-px88-56v2-r67vCGA-q222-wv7h-7rqpCGA-q465-v5j3-qc35CGA-q58r-j6hc-jr5vCGA-q67r-wx34-p9f6CGA-qmmv-cx4v-94wxCGA-qmvw-3q7p-9w7gCGA-qvj5-v7mx-pxp5CGA-r2xw-35w2-35crCGA-r3xj-j94x-x654CGA-r48r-fcw8-pp3mCGA-r54h-j4wj-p567CGA-r98h-hwjw-cv3vCGA-r9g4-9j5x-w37rCGA-rfrj-wgqj-j8qxCGA-rg48-62r7-72cqCGA-rg5q-8xw7-jv69CGA-rgwf-p795-xw67CGA-rjcg-vppm-268xCGA-rp8w-mh42-pf2jCGA-rr9p-ccvh-xfwpCGA-rwmp-cgmc-4hcrCGA-v3gp-76h9-3878CGA-v4q4-6rxf-927jCGA-v58v-qcxp-pmhcCGA-v6ph-5qf3-v2jvCGA-v7cm-5h36-7fp5CGA-vc44-64hg-fpgwCGA-vhg9-jqm5-9mqgCGA-vqq7-vw5q-qjfpCGA-vrcj-7cff-9q5vCGA-vrg5-v23w-m2xfCGA-vwvp-fm5r-jx5xCGA-w3hm-mw6g-6r86CGA-w48q-7frw-qm9qCGA-w6gf-grj4-hgm7CGA-w72r-gc2x-36mxCGA-wcj9-6f42-mv8hCGA-wf8v-x42h-38rjCGA-wfxw-7x38-rxmqCGA-wg7x-2cq5-46rfCGA-wgvx-q35j-rfw3CGA-wj9w-59r4-hm5vCGA-wpp7-qrch-cp75CGA-wv6m-7qm2-ccq2CGA-wv6r-jrq6-rpxxCGA-wvv2-7fc2-8w54CGA-wxqr-v687-46rqCGA-x24j-33wc-hg9vCGA-x45q-q2h7-cv9gCGA-x47j-4fff-5523CGA-x59f-qj89-qx66CGA-x87h-26h7-3rpvCGA-x9j7-m76r-5r23CGA-xc85-4mj8-8xhjCGA-xf7r-mcw2-7xwfCGA-xfhv-g3cq-76jpCGA-xhxr-mgvc-qc2cCGA-xpjf-q9pg-46mrCGA-xq66-32x2-338vCGA-xrvv-f7wx-mmf9CGA-2hr6-272h-p853CGA-8jg6-j44j-rf5fCGA-c676-vqqq-g2jhCGA-gp4h-hjwq-9769CGA-hh59-vggf-vcwjCGA-hxx4-57w6-8642CGA-mc44-rjv8-588qCGA-qqq9-7fmf-63xpCGA-m2jx-x28m-9rv3
Analyzed
Published: 06 Nov 2025, 20:02
Last modified:06 Nov 2025, 21:32

Vulnerability Summary

Overall Risk (default)
medium
44/100
CVSS Score
8.4 HIGH
v4.0 (cve.org)
EPSS Score
0.56% LOW
1% probability +0.55%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

06 Nov 2025, 20:02
Published
Vulnerability first disclosed
06 Nov 2025, 21:32
Last Modified
Vulnerability information updated

Description

runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of `/dev/pts/$n` to `/dev/console` as configured for all containers that allocate a console). This happens after `pivot_root(2)`, so this cannot be used to write to host files directly -- however, as with CVE-2025-31133, this can load to denial of service of the host or a container breakout by providing the attacker with a writable copy of `/proc/sysrq-trigger` or `/proc/sys/kernel/core_pattern` (respectively). This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.

CVSS Metrics

  • v4.0HIGHScore: 8.4CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H
  • v4.0HIGHScore: 8.4CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v4.0HIGHScore: 7.3CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.56% Percentile: 46%

Techniques & Countermeasures

  • CWE-61UNIX Symbolic Link (Symlink) Following

    The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

  • CWE-363Race Condition Enabling Link Following

    The product checks the status of a file or directory before accessing it, which produces a race condition in which the file can be replaced with a link before the access is performed, causing the product to access the wrong file.

Affected Systems

  • chainguardazure-vnet-cni

    < 1.7.4-r2

  • chainguardbuildah

    < 1.42.0-r1

  • chainguardcluster-autoscaler-1.31

    < 1.31.5-r4 | < 1.31.5-r1

  • chainguardcluster-autoscaler-fips-1.31

    < 1.31.5-r1 | < 1.31.5-r5

  • chainguardctop

    all

  • chainguardctop-fips

    all

  • chainguardeks-distro-1.29

    < 1.29.53-r1

  • chainguardeks-distro-1.30

    < 1.30.46-r1

  • chainguardeks-distro-1.31

    < 1.31.35-r1

  • chainguardeks-distro-1.32

    < 1.32.28-r1

  • chainguardeks-distro-coredns-1.30

    < 1.30.46-r1

  • chainguardeks-distro-coredns-1.31

    < 1.31.35-r1

  • chainguardeks-distro-coredns-1.32

    < 1.32.28-r1

  • chainguardeks-distro-coredns-fips-1.29

    < 1.29.53-r1

  • chainguardeks-distro-coredns-fips-1.30

    < 1.30.46-r1

  • chainguardeks-distro-fips-1.29

    < 1.29.53-r1

  • chainguardeks-distro-fips-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-apiserver-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-apiserver-1.31

    < 1.31.35-r1

  • chainguardeks-distro-kube-apiserver-1.32

    < 1.32.28-r1

  • chainguardeks-distro-kube-apiserver-fips-1.29

    < 1.29.53-r1

  • chainguardeks-distro-kube-apiserver-fips-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-controller-manager-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-controller-manager-1.31

    < 1.31.35-r1

  • chainguardeks-distro-kube-controller-manager-1.32

    < 1.32.28-r1

  • chainguardeks-distro-kube-controller-manager-fips-1.29

    < 1.29.53-r1

  • chainguardeks-distro-kube-controller-manager-fips-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-controller-manager-fips-1.32

    < 1.32.28-r1

  • chainguardeks-distro-kube-proxy-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-proxy-1.31

    < 1.31.35-r1

  • chainguardeks-distro-kube-proxy-fips-1.29

    < 1.29.53-r1

  • chainguardeks-distro-kube-proxy-fips-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-proxy-fips-1.32

    < 1.32.28-r1

  • chainguardeks-distro-kube-scheduler-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kube-scheduler-1.31

    < 1.31.35-r1

  • chainguardeks-distro-kube-scheduler-1.32

    < 1.32.28-r1

  • chainguardeks-distro-kube-scheduler-fips-1.29

    < 1.29.53-r1

  • chainguardeks-distro-kube-scheduler-fips-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kubernetes-pause-1.30

    < 1.30.46-r1

  • chainguardeks-distro-kubernetes-pause-1.31

    < 1.31.35-r1

  • chainguardfalco-no-driver

    < 0.43.0-r0

  • chainguardgosu-1.11

    all

  • chainguardgrafana-alloy

    < 1.11.3-r1

  • chainguardgrafana-alloy-fips

    < 1.11.3-r2

  • chainguardharvester-fips

    < 0

  • chainguardharvester-fips-upgrade-helper

    < 0

  • chainguardharvester-fips-webhook

    < 0

  • chainguardharvester-upgrade-helper

    < 0

  • chainguardharvester-webhook

    < 0

  • chainguardk3s-1.32

    < 1.32.9.1-r2

Showing first 50 affected entries in server-rendered view.

References (13)