Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 9: MGASA-2025-0271 Opencontainers-runc Important Denial of Service

mageia
Calendar Grey November 9, 2025
Dist Mageia Esm H88
Updated opencontainers-runc packages address vulnerabilities impacting Mageia 9, enhancing system security and stability.
MGASA-2025-0271 - Updated opencontainers-runc packages fix security vulnerabilities

Summary

Description: The way masked paths are implemented in runc can be exploited to cause the host system to crash or halt (CVE-2025-31133) and a flaw in /dev/console bind-mounts can lead to container escape (CVE-2025-52565). Also, arbitrary write gadgets and procfs write redirects could be used to engineer container escape and denial of service (CVE-2025-52881).

References

- https://bugs.mageia.org/show_bug.cgi?id=34719

- https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2

- https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm

- https://www.openwall.com/lists/oss-security/2025/11/05/3

- https://www.cve.org/CVERecord?id=CVE-2025-31133

- https://www.cve.org/CVERecord?id=CVE-2025-52565

- https://www.cve.org/CVERecord?id=CVE-2025-52881

Resolution

SRPMS

- 9/core/opencontainers-runc-1.2.8-2.1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 09 Nov 2025
URL: https://advisories.mageia.org/MGASA-2025-0271.html
Type: security
CVE: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here