{"id":"CVE-2025-31133","title":"runc is a CLI tool for spawning and running containers according to the OCI specification","summary":"runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the so…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-61","CWE-363"],"vendor":"linuxfoundation","product":"runc","affected":["runc < 1.2.8","runc >= 1.3.0, < 1.3.3","runc = 1.4.0"],"patched":["runc 1.3.3"],"published":"2025-11-06","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-31133","references":[{"url":"https://github.com/opencontainers/runc/commit/1a30a8f3d921acbbb6a4bb7e99da2c05f8d48522","label":"security-advisories@github.com"},{"url":"https://github.com/opencontainers/runc/commit/5d7b2424072449872d1cd0c937f2ca25f418eb66","label":"security-advisories@github.com"},{"url":"https://github.com/opencontainers/runc/commit/8476df83b534a2522b878c0507b3491def48db9f","label":"security-advisories@github.com"},{"url":"https://github.com/opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64","label":"security-advisories@github.com"},{"url":"https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2","label":"security-advisories@github.com"}],"tags":["nvd","exploit-available"],"epss":0.00844,"epssPercentile":0.56669,"exploits":{"github":3,"githubRepos":["https://github.com/skynet-f-nvidia/CVE-2025-31133","https://github.com/C-h4ck-0/Learn-about-cve-2025-31133-poc","https://github.com/scherepiuk/container-escape-ebpf"],"checkedAt":"2026-10-07T21:54:50.411Z"},"exploitAvailable":true,"ingestedAt":"2026-10-07T21:54:14.965Z","slug":"CVE-2025-31133","body":"## Overview\n\nrunc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.\n\n## Affected\n\n- `runc < 1.2.8`\n- `runc >= 1.3.0, < 1.3.3`\n- `runc = 1.4.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `runc 1.3.3`","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":42.9,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[]}