Story perspectives
Critical runC Vulnerabilities Allow Potential Container Escapes
11/10/2025
1 of 1
Story summary
- Three critical vulnerabilities in runC, the container runtime for Docker and Kubernetes, could allow attackers to bypass container isolation and gain root access to host systems.
- Attackers can manipulate symbolic links and race conditions during container creation to achieve a complete container escape.
- Patches exist in runC versions 1.2.8, 1.3.3, and 1.4.0-rc.3; organizations should update immediately and monitor for suspicious activity, while no active exploitation has been reported yet.
