CVE-2025-52881Patch(linuxfoundation / runc)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch linuxfoundation runc systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61CWE-363

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • runc

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Peaked 1d ago at 2 mentions (2026-07-10); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
runc

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-25: 1Mentions · 2026-04-30: 1Mentions · 2026-07-10: 2Mentions · 2026-08-31: 1PoC Mentioned / Linked · 2026-08-31: 1Active Exploitation · 2026-07-10: 2Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-03-25: 1Technical Details · 2026-07-10: 2Technical Details · 2026-08-31: 103-2504-3007-1008-31
Signal classification3 categories
Patch
240.0%
Active Exploitation
240.0%
PoC
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-251
Patch1
2026-04-301
Patch1
2026-07-102
Active Exploitation2
2026-08-311
PoC1
Full discourse5 posts
  • UNRAID@UnraidOfficial
    Patch

    Security first. 🛡️ Unraid 7.3.0-rc.1 brings a major security-forward reason to upgrade your test servers. Patched: 🔒 Docker 29.3.1 runc fixes (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) 🔒 bind updated for outstanding CVEs Plus: AMD XDNA support & QEMU 10.2.2! https://t.co/v6PqQN8CdT

    Post summary

    The tweet announces that Unraid 7.3.0‑rc.1 includes patches to Docker runc for CVE‑2025‑31133, CVE‑2025‑52565, and CVE‑2025‑52881, encouraging users to upgrade.

    2001301.6K
    12.6K followersView on X
  • felipehuici@felipehuici
    Active Exploitation

    If you're running critical or multi-tenant workloads on containers, you're playing with fire. The CVE record keeps proving it: - CVE-2024-21626 — Leaky Vessels: runc container escape, host filesystem access - CVE-2025-23266 — NVIDIAScape: CVSS 9.0, triggered by a 3-line Dockerfile - CVE-2025-52881 — runc procfs write-redirect: full breakout, actively exploited in the wild by mid-2026 - CVE-2025-38617 — Linux kernel packet-socket: full container escape via user namespaces This is not a 2024 phenomenon that someone will eventually fix. The November-2025 runc trio (CVE-2025-31133 / -52565 / -52881) moved from disclosure to confirmed in-the-wild exploitation, affecting Docker, containerd and every major managed Kubernetes service. Escapes never stopped — 2024-2025 brought a fresh surge, and by 2026 the worst of them are being exploited for real. Containers don't contain. ⚠️ 📄 Full blog post: https://unikraft.com/blog/the-mighty-microvm

    Post summary

    The post highlights that multiple container‑escape CVEs, notably runc and kernel related ones, are being actively exploited in the wild and urges readers to be aware of the ongoing threat.

    00066569
    909 followersView on X
  • shubham kumar@kumar98_shubham
    PoC

    Proof, not theory. Jan 2024, CVE-2024-21626: runc leaked a file descriptor. The container reached the host filesystem. Mount namespace was intact. Escape was an fd runc forgot to close. 2025: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881. Mount races. Write to protected host paths from inside the container.

    Post summary

    The post confirms proofs of concept for CVE-2024-21626 and several 2025 CVEs, detailing technical exploitation paths (e.g., leaked fd and mount races), but offers no active exploitation evidence, exploit code, patch, or debunking.

    1000027
    45 followersView on X
  • Jérôme Jaggi@JeromeJaggi
    Active Exploitation

    Can someone explain to me why people still trust containers? - CVE-2024-21626 (Leaky Vessels) - CVE-2025-23266 (NVIDIAScape, CVSS 9.0, a 3-line Dockerfile) - CVE-2025-52881 (runc procfs write-redirect, actively exploited in the wild by mid-2026). Those are some prominent examples but there are lots more and they are recurring, publicly disclosed vulnerabilities affecting Docker, containerd, and every major managed Kubernetes service. Also, the trend from 2024 to 2026 is not improving 😅 Containers are great for packaging and distribution - but the problem is still that a shared-kernel container was never architected to be a hard, multi-tenant security boundary, and the CVE record keeps proving it. Long live the microVM 🎉 🔗 Read the full blog post here: https://unikraft.com/blog/the-mighty-microvm

    Post summary

    The post discusses container-related CVEs and notes that CVE‑2025‑52881 is already being exploited in the wild, though it lacks evidence of PoCs, patches, or countermeasures.

    0001040
    15 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical CVE-2025-52881 in Fedora 42,43 container networking plugins enables container escape and DoS - upgrade containernetworking-plugins to v1.9.1 immediately. https://threatcluster.io/cluster/critical-vulnerability-in-fedora-container-networking-plugin-c204d804

    Post summary

    The post announces CVE-2025-52881 affecting Fedora container networking plugins and urges users to upgrade to a patched version immediately.

    00010194
    114 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationrunc---
Applinuxfoundationrunc1.4.0--
Applinuxfoundationrunc1.4.0--

Explore more