Database/Container, Kubernetes & orchestration
runc: Attacker misdirects runc writes to /proc via racing symlinks
CVE-2025-52881Container, Kubernetes & orchestrationcurated
Impact
Attacker misdirects runc writes to /proc via racing symlinks; can defeat LSM labelling and escape
Who can reach it
Any tenant workload
What to do
Replace runc on all nodes; drain required
Fleet impact
How widespread
Universal - same runc version range
Cost to remediate
node-drain - runc upgrade + container recreation across the whole fleet
Why it hits the whole fleet
LSM (AppArmor/SELinux) bypass that makes arbitrary procfs writes easy, turning the other two into reliable host root; AWS, Alibaba and every distro shipped emergency runc rebuilds
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.