Three high-severity vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) were disclosed in runc, the default container runtime for Docker, Podman, and Kubernetes. All three exploit race conditions to bypass restrictions on writing to /proc files, enabling full container breakouts. Attackers can leverage malicious

4m read timeFrom cncf.io
Post cover image
Table of contents
The vulnerabilitiesExploitation scenarios and threat modelKubernetes and cloud native implicationsAffected versions and patchesMitigationsThe bigger picture: Secure-by-default configurationsCredits

Sort: