Junglewise Threat Intelligence

CVE-2025-52565: GO-2025-4096 - Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc

CVE-2025-52565 · Severity: high · CVSS 4 · Published 2025-11-18

Technologies: Open Container Initiative Runc, Amazon AWS, github.com/opencontainers/runc (Go). Vendors: AWS, Open Container Initiative, Amazon, Go.

Executive brief

Multiple security vulnerabilities have been identified in runc, a core component used by many container platforms to launch and manage containers. If exploited, these flaws could allow a malicious container to potentially escape its isolation or gain unauthorized access to the underlying host system. While AWS has stated there is no risk of one customer accessing another's data, organizations using these tools to isolate their own internal workloads should apply updates to prevent internal security breaches.

Technical details

Three vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) affect the runc component used across various container management systems. The issues occur during the container launch process and can potentially be exploited by a malicious container image or process to break out of the containerized environment or escalate privileges on the host. The attack vector is local, requiring the ability to run a container on the target system. AWS has released patched versions of Amazon Linux, Bottlerocket, and updated AMIs for ECS and EKS. Users of self-managed container environments are advised to update runc to version 1.3.2-2 or later.

Affected products

  • Open Container Initiative (OCI) runc < 1.3.2-2
  • AWS Amazon Linux 2 / 2023
  • AWS Bottlerocket
  • AWS Amazon ECS / EKS
  • AWS Finch

CVE identifiers

  • CVE-2025-52565
  • CVE-2025-31133
  • CVE-2025-52881

Timeline

  • 2025-11-05: disclosed
  • 2025-11-05: patched: AWS began rolling out patches across affected services

References

Related threats