Three high-severity vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) were disclosed in runc, the default container runtime for Docker, Podman, and Kubernetes. All three exploit race conditions to bypass restrictions on writing to /proc files, enabling full container breakouts. Attackers can leverage malicious
Table of contents
The vulnerabilitiesExploitation scenarios and threat modelKubernetes and cloud native implicationsAffected versions and patchesMitigationsThe bigger picture: Secure-by-default configurationsCreditsSort: