GO-2025-4097

Source
https://pkg.go.dev/vuln/GO-2025-4097
Import Source
https://vuln.go.dev/ID/GO-2025-4097.json
JSON Data
https://api.test.osv.dev/v1/vulns/GO-2025-4097
Aliases
Downstream
Published
2025-11-18T15:44:15Z
Modified
2026-07-17T21:10:37.339128504Z
Summary
Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc
Details

Container escape with malicious config due to /dev/console mount and related races in github.com/opencontainers/runc

Database specific
{
    "url": "https://pkg.go.dev/vuln/GO-2025-4097",
    "review_status": "REVIEWED"
}
References

Affected packages

Go / github.com/opencontainers/runc

Package

Name
github.com/opencontainers/runc
View open source insights on deps.dev
Purl
pkg:golang/github.com/opencontainers/runc

Affected ranges

Type
SEMVER
Events
Introduced
1.0.0-rc3
Fixed
1.2.8
Introduced
1.3.0-rc.1
Fixed
1.3.3
Introduced
1.4.0-rc.1
Fixed
1.4.0-rc.3

Ecosystem specific

{
    "imports": [
        {
            "path": "github.com/opencontainers/runc/libcontainer"
        },
        {
            "symbols": [
                "CloneBinary",
                "CloneSelfExe",
                "sealFile"
            ],
            "path": "github.com/opencontainers/runc/libcontainer/exeseal"
        }
    ]
}

Database specific

source
"https://vuln.go.dev/ID/GO-2025-4097.json"