Some Docker containers may not be as secure as they like, experts warn



  • Three runC flaws could allow container escape and host access with admin privileges
  • Bugs affect Docker/Kubernetes setups using custom mounts and older runC versions
  • Mitigation includes user namespaces and rootless containers to limit exploit impact

The runC container runtime, used in both Docker and Kubernetes, carried three high-severity vulnerabilities that could be used to access the underlying system, security researchers have warned.

Security researcher Aleksa Sarai disclosed discovering CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881, three bugs that, when chained together, granted access to the underlying container host with admin privileges.


https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1920-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img