[Apollo] Advisories Statistics light light Login

RLSA-2025:20957

Security Mirrored from RHSA-2025:20957
Issued at: 2025-11-21
Updated at: 2025-11-23

Synopsis

Important: runc security update



Description

The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.

Security Fix(es):

* runc: container escape via 'masked path' abuse due to mount race conditions (CVE-2025-31133)

* runc: container escape with malicious config due to /dev/console mount and related races (CVE-2025-52565)

* runc: container escape and denial of service due to arbitrary write gadgets and procfs write redirects (CVE-2025-52881)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 9 aarch64 Rocky Linux 9 ppc64le Rocky Linux 9 s390x Rocky Linux 9 x86_64

Fixes

2404705 2404708 2404715

CVEs

CVE-2025-31133 CVE-2025-52565 CVE-2025-52881

Affected packages

Rocky Linux 9 aarch64 - AppStream

runc-4:1.3.0-4.el9_7.aarch64.rpm runc-4:1.3.0-4.el9_7.src.rpm runc-debuginfo-4:1.3.0-4.el9_7.aarch64.rpm runc-debugsource-4:1.3.0-4.el9_7.aarch64.rpm

Rocky Linux 9 ppc64le - AppStream

runc-4:1.3.0-4.el9_7.ppc64le.rpm runc-4:1.3.0-4.el9_7.src.rpm runc-debuginfo-4:1.3.0-4.el9_7.ppc64le.rpm runc-debugsource-4:1.3.0-4.el9_7.ppc64le.rpm

Rocky Linux 9 s390x - AppStream

runc-4:1.3.0-4.el9_7.s390x.rpm runc-4:1.3.0-4.el9_7.src.rpm runc-debuginfo-4:1.3.0-4.el9_7.s390x.rpm runc-debugsource-4:1.3.0-4.el9_7.s390x.rpm

Rocky Linux 9 x86_64 - AppStream

runc-4:1.3.0-4.el9_7.src.rpm runc-4:1.3.0-4.el9_7.x86_64.rpm runc-debuginfo-4:1.3.0-4.el9_7.x86_64.rpm runc-debugsource-4:1.3.0-4.el9_7.x86_64.rpm