CVE-2025-52565Disclosure(linuxfoundation / runc)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch linuxfoundation runc systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of `/dev/pts/$n` to `/dev/console` as configured for all containers that allocate a console). This happens after `pivot_root(2)`, so this cannot be used to write to host files directly -- however, as with CVE-2025-31133, this can load to denial of service of the host or a container breakout by providing the attacker with a writable copy of `/proc/sysrq-trigger` or `/proc/sys/kernel/core_pattern` (respectively). This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61CWE-363

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • runc

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-27); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
runc

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-27: 1Mentions · 2026-04-16: 1Mentions · 2026-04-30: 1Mentions · 2026-08-31: 1PoC Mentioned / Linked · 2026-08-31: 1Active Exploitation · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-16: 1Technical Details · 2026-08-31: 102-2704-1604-3008-31
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
PoC
125.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-271
Disclosure1
2026-04-161
Disclosure1
2026-04-301
Patch1
2026-08-311
PoC1
Full discourse4 posts
  • UNRAID@UnraidOfficial
    Patch

    Security first. 🛡️ Unraid 7.3.0-rc.1 brings a major security-forward reason to upgrade your test servers. Patched: 🔒 Docker 29.3.1 runc fixes (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) 🔒 bind updated for outstanding CVEs Plus: AMD XDNA support & QEMU 10.2.2! https://t.co/v6PqQN8CdT

    Post summary

    Unraid 7.3.0‑rc.1 includes patches for multiple CVEs—specifically updates to Docker runc and bind—encouraging users to apply the update.

    2001301.6K
    12.6K followersView on X
  • shubham kumar@kumar98_shubham
    PoC

    Proof, not theory. Jan 2024, CVE-2024-21626: runc leaked a file descriptor. The container reached the host filesystem. Mount namespace was intact. Escape was an fd runc forgot to close. 2025: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881. Mount races. Write to protected host paths from inside the container.

    Post summary

    The text reveals an existing proof of concept for CVE‑2024‑21626 involving an runc file descriptor leak and outlines upcoming 2025 CVEs that exploit mount races to write to protected host files, but no active exploitation or patch information is provided.

    1000027
    45 followersView on X
  • Yoko Hasebe (長谷部洋子 岩国市)@yokotf4yur
    Disclosure

    https://youtube.com/shorts/6BSWMZkihUI?si=YmepQEcWwfKlNBnJ ## ✅ 確認済み:最新 Azure 脆弱性・CVE 情報(2025〜2026年) ### 🔴 最重要:CVE-2025-55241(Entra ID) **CVSS 10.0 / Critical** Microsoft Entra IDのトークン検証不備により、攻撃者が任意のユーザー(グローバル管理者を含む)をすべてのテナントにわたって偽装できる脆弱性。発見者はセキュリティ研究者 Dirk-Jan Mollema(2025年7月14日報告)で、Microsoftは3日後の7月17日に修正を完了。顧客側の対応は不要。野生での悪用は確認されていない。 [The Hacker News](https://thehackernews.com/2025/09/microsoft-patches-critical-entra-id.html) 技術的な原因は、レガシーAzure AD Graph APIのトークン検証の欠陥。攻撃者が自テナントで取得した「Actorトークン」を他テナントに使い回すことで、MFAや条件付きアクセスポリシーをバイパスしてテナント全体を侵害できる状態だった。 [Uvcyber](https://www.uvcyber.com/resources/reports/threat-advisory-azure-entra-id-vulnerability) **対応アクション:** - Azure AD Graph API(2025年8月31日に廃止済み)への依存を排除 - Microsoft Graphへ移行 - PIM(Privileged Identity Management)の導入 --- ### 🔴 CVE-2026-20965(Windows Admin Center) **High / テナント全体への横断アクセス** Windows Admin Center の Azure SSO実装に高深刻度の脆弱性。不正なトークン検証により、Azure VMおよびArc接続システム全体への不正アクセスが可能。Microsoftは2026年1月13日リリースのv0.70.00で修正。それ以前のバージョンは依然として脆弱。 [Gopher](https://www.gopher.security/news/critical-azure-entra-id-vulnerability-allows-tenant-wide-compromise) --- ### 🟠 AKS(Azure Kubernetes Service)関連 CVE 2025年3月、Kubernetes nginx ingress controllerに複数の脆弱性が開示された:CVE-2025-1974(Critical)、CVE-2025-1098(High)、CVE-2025-1097(High)、CVE-2025-24514(High)、CVE-2025-24513(Medium)。ingress-nginxを使用しているクラスターが対象。AKSのマネージドアドオンはパッチ済みだが、独自導入の場合はv1.11.5またはv1.12.1へのアップデートが必要。 [Microsoft Learn](https://learn.microsoft.com/en-us/azure/aks/security-bulletins/overview) また、runcに関するCVE-2025-31133、CVE-2025-52565、CVE-2025-52881も開示済み。新しいノードイメージがロールアウトされている。 [Microsoft Learn](https://learn.microsoft.com/en-us/azure/aks/security-bulletins/overview) --- ### 🟠 Azure Bastion CVE-2025-49752 **CVSS 10.0 / Critical** Azure BastionにCVE-2025-49752として追跡される重大な認証バイパス脆弱性。単一のネットワークリクエストでAzure VMへの管理者アクセスを取得できる可能性がある。CWE-294(認証バイパス)に分類され、事前認証・ユーザー操作なしでリモート悪用が可能。 [Zeropath](https://zeropath.com/blog/azure-bastion-cve-2025-49752) --- ### 🟡 2026年4月 Patch Tuesday(最新・4月16日) Microsoftは2026年4月のPatch Tuesdayで163件のCVEを修正。うち8件がCritical評価。CVE-2026-32201はSharePointのゼロデイで実際に悪用された。 [Tenable®](https://www.tenable.com/blog/microsofts-april-2026-patch-tuesday-addresses-163-cves-cve-2026-32201) 主なCVE: - **CVE-2026-33826**:Windows Active Directory RCE(Critical、CVSS 8.0) - **CVE-2026-33824**:Windows IKE RCE(Critical、CVSS 9.8、未認証攻撃可能) - **CVE-2026-33825**:Microsoft Defender 権限昇格(Important) --- ### 📋 信頼性まとめ | CVE | サービス | 深刻度 | 確認状況 | |-----|---------|--------|---------| | CVE-2025-55241 | Entra ID | CVSS 10.0 | ✅ 実在 | | CVE-2025-49752 | Azure Bastion | CVSS 10.0 | ✅ 実在 | | CVE-2026-20965 | Windows Admin Center | High | ✅ 実在 | | CVE-2025-1974 | AKS nginx | Critical | ✅ 実在 | | CVE-2026-32201 | SharePoint | 実悪用確認 | ✅ 実在 | --- 特定のCVEの詳細や、対策方法について知りたい場合はお知らせください!←Claude

    Post summary

    The post serves as a comprehensive disclosure of several high‑severity Azure and Microsoft CVEs, detailing their technical causes, patch status, and known exploitation activity for certain assets.

    00000231
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Dell ❗ CVE-2025-53066 ❗ CVE-2025-52565 ❗ CVE-2025-38180 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-dell-3/ https://t.co/sMMKXtDq5T

    Post summary

    The tweet lists three Dell product CVEs and points to external links for additional information.

    00000121
    6.6K followersView on X
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationrunc---
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.0.0--
Applinuxfoundationrunc1.4.0--
Applinuxfoundationrunc1.4.0--

Explore more