USN-7851-1

Source
https://ubuntu.com/security/notices/USN-7851-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7851-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-7851-1
Upstream
Related
Published
2025-11-04T15:36:31.410549Z
Modified
2025-11-10T05:46:18Z
Summary
runc-app, runc-stable vulnerabilities
Details

Lei Wang and Li Fubang discovered that runC incorrectly handled masked paths. An attacker could possibly replace a container's /dev/null with a symlink to some other procfs file and possibly escape a container. (CVE-2025-31133)

Lei Wang and Li Fubang discovered that runC incorrectly handled the /dev/console bind-mounts. An attacker could potentially exploit this issue to build-mount a symlink and escape a container. (CVE-2025-52565)

Li Fubang and Tõnis Tiigi discovered that the fix for CVE-2019-16884 was incomplete. An attacker could possibly use this issue to cause a denial of service or escape the container. (CVE-2025-52881)

References

Affected packages

Ubuntu:22.04:LTS / runc-app

Package

Name
runc-app
Purl
pkg:deb/ubuntu/runc-app@1.3.3-0ubuntu1~22.04.2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3-0ubuntu1~22.04.2

Affected versions

1.*

1.1.12-0ubuntu2~22.04.1
1.2.5-0ubuntu1~22.04.1
1.3.0-0ubuntu2~22.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.3.3-0ubuntu1~22.04.2",
            "binary_name": "runc"
        }
    ]
}

Database specific

cves_map

{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-31133"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-52565"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-52881"
        }
    ],
    "ecosystem": "Ubuntu:22.04:LTS"
}

Ubuntu:24.04:LTS / runc-app

Package

Name
runc-app
Purl
pkg:deb/ubuntu/runc-app@1.3.3-0ubuntu1~24.04.2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3-0ubuntu1~24.04.2

Affected versions

1.*

1.1.10-0ubuntu1
1.1.12-0ubuntu1
1.1.12-0ubuntu2
1.1.12-0ubuntu3
1.1.12-0ubuntu3.1
1.2.5-0ubuntu1~24.04.1
1.3.0-0ubuntu2~24.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.3.3-0ubuntu1~24.04.2",
            "binary_name": "runc"
        }
    ]
}

Database specific

cves_map

{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-31133"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-52565"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-52881"
        }
    ],
    "ecosystem": "Ubuntu:24.04:LTS"
}

Ubuntu:25.10 / runc-app

Package

Name
runc-app
Purl
pkg:deb/ubuntu/runc-app@1.3.3-0ubuntu1~25.10.2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3-0ubuntu1~25.10.2

Affected versions

1.*

1.2.5-0ubuntu1
1.3.0-0ubuntu1
1.3.0-0ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.3.3-0ubuntu1~25.10.2",
            "binary_name": "runc"
        }
    ]
}

Database specific

cves_map

{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-31133"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-52565"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-52881"
        }
    ],
    "ecosystem": "Ubuntu:25.10"
}

Ubuntu:25.10 / runc-stable

Package

Name
runc-stable
Purl
pkg:deb/ubuntu/runc-stable@1.3.3-0ubuntu1~25.10.2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3-0ubuntu1~25.10.2

Affected versions

1.*

1.3.0-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.3.3-0ubuntu1~25.10.2",
            "binary_name": "runc-stable"
        }
    ]
}

Database specific

cves_map

{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-31133"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-52565"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-52881"
        }
    ],
    "ecosystem": "Ubuntu:25.10"
}

Ubuntu:25.04 / runc-app

Package

Name
runc-app
Purl
pkg:deb/ubuntu/runc-app@1.3.3-0ubuntu1~25.04.2?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3-0ubuntu1~25.04.2

Affected versions

1.*

1.1.12-0ubuntu4
1.2.5-0ubuntu1
1.3.0-0ubuntu2~25.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.3.3-0ubuntu1~25.04.2",
            "binary_name": "runc"
        }
    ]
}

Database specific

cves_map

{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-31133"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-52565"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "high"
                }
            ],
            "id": "CVE-2025-52881"
        }
    ],
    "ecosystem": "Ubuntu:25.04"
}