Some Docker containers may not be as secure as they would like, experts warn



  • Three runC flaws could allow container escape and host access with administrator privileges
  • Bugs affect Docker/Kubernetes configurations using custom mounts and older versions of runC
  • Mitigation includes user namespaces and rootless containers to limit the impact of exploitation.

The runC container runtime, used in both Docker and Kubernetes, had three high-severity vulnerabilities that could be used to access the underlying system, security researchers warned.

Security researcher Aleksa Sarai revealed she discovered CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881, three bugs that, when chained together, granted access to the underlying container host with administrator privileges.



Leave a Comment

Your email address will not be published. Required fields are marked *