UNIX symbolic link following in runc - CVE-2025-31133

 

UNIX symbolic link following in runc - CVE-2025-31133

Published: November 5, 2025 / Updated: April 10, 2026


Vulnerability identifier: #VU118104
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31133
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a symlink following issue within the maskedPaths feature. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.

Successful exploitation of this vulnerability may result in privilege escalation.


Affected software

runc
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Containers Module
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Fedora
Arista CloudEOS VM
Arista Extensible Operating System (EOS)
buildah
Red Hat OpenShift Container Platform
Maximo Application Suite - IoT Component
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
toolbox-tests
toolbox
udica
python-eventlet (Red Hat package)
docker-runc
slirp4netns
runc
runc (Red Hat package)
runc-debuginfo
runc-doc
oci-seccomp-bpf-hook
runc-app (Ubuntu package)
containernetworking-plugins
aardvark-dns
netavark
alloy-debuginfo
alloy
fuse-overlayfs
crun (Red Hat package)
crun
skopeo
skopeo-tests
cri-o (Red Hat package)
buildah-tests
buildah
containers-common
conmon
haproxy (Red Hat package)
container-selinux
criu-devel
criu-libs
python3-criu
criu
crit
libslirp
libslirp-devel
python3-podman
podman (Red Hat package)
podman-remote
podman
podman-catatonit
podman-tests
podman-gvproxy
podman-docker
podman-plugins
podman-debuginfo
podmansh
podman-remote-debuginfo
kernel (Red Hat package)
kernel-rt (Red Hat package)
cockpit-podman

How to mitigate CVE-2025-31133

Install updates from vendor's website.

runc - addressed in versions 1.2.8, 1.3.3, 1.4.0 rc.3
buildah - update to 1.33.14
Maximo Application Suite - IoT Component - addressed in versions 8.7.29, 8.8.25, 9.0.15, 9.1.6
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
python-eventlet (Red Hat package) - update to 0.33.1-7.el9
docker-runc - update to 1.0.0 rc3-229
slirp4netns - update to 1.2.3-1
runc - addressed in versions 1.2.5-2, 1.2.8-1
runc (Red Hat package) - addressed in versions 1.2.5-3.el9_6, 1.2.9-1.el9_0, 1.2.9-1.el9_2.1, 1.2.9-1.rhaos4.16.el8, 1.2.9-1.rhaos4.16.el9, 1.2.9-1.rhaos4.17.el8, 1.2.9-1.rhaos4.17.el9, 1.2.9-1.rhaos4.18.el8, 1.2.9-1.rhaos4.18.el9, 1.3.0-4.el9_7
runc - addressed in versions 1.2.7-16.67.1, 1.2.7-150000.80.1, 1.3.3-16.70.1, 1.3.3-150000.85.1
runc-debuginfo - addressed in versions 1.2.7-16.67.1, 1.2.7-150000.80.1, 1.3.3-16.70.1, 1.3.3-150000.85.1
runc-doc - update to 1.2.8-1
oci-seccomp-bpf-hook - update to 1.2.10-1
runc-app (Ubuntu package) - addressed in versions 1.3.3-0ubuntu1~22.04.2, 1.3.3-0ubuntu1~22.04.3, 1.3.3-0ubuntu1~24.04.2, 1.3.3-0ubuntu1~24.04.3, 1.3.3-0ubuntu1~25.04.2, 1.3.3-0ubuntu1~25.04.3, 1.3.3-0ubuntu1~25.10.2, 1.3.3-0ubuntu1~25.10.3
runc - update to 1.3.3-1.fc44
containernetworking-plugins - update to 1.4.0-6.0.1
aardvark-dns - update to 1.10.1-2.0.1
netavark - update to 1.10.3-1.0.1
alloy-debuginfo - update to 1.12.2-150700.15.15.1
alloy - update to 1.12.2-150700.15.15.1
fuse-overlayfs - update to 1.13-1.0.1
crun (Red Hat package) - update to 1.14.3-1.el9_0
crun - update to 1.14.3-2
skopeo - update to 1.14.5-4.0.1
skopeo-tests - update to 1.14.5-4.0.1
cri-o (Red Hat package) - addressed in versions 1.25.5-32.rhaos4.12.git6120b13.el8, 1.29.13-11.rhaos4.16.git979a5e6.el8, 1.29.13-11.rhaos4.16.git979a5e6.el9, 1.31.13-3.rhaos4.18.gite0b87e5.el8, 1.31.13-3.rhaos4.18.gite0b87e5.el9
buildah-tests - update to 1.33.12-2
buildah - update to 1.33.12-2
containers-common - update to 1-82.0.1
conmon - update to 2.1.10-1
haproxy (Red Hat package) - update to 2.8.10-2.rhaos4.18.el9
container-selinux - update to 2.229.0-2
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
python3-podman - update to 4.9.0-3
podman (Red Hat package) - addressed in versions 4.9.4-19.rhaos4.16.el8, 4.9.4-20.rhaos4.16.el9, 5.2.2-6.rhaos4.18.el8, 5.2.2-12.rhaos4.17.el8, 5.2.2-12.rhaos4.17.el9, 5.2.2-14.rhaos4.18.el9
podman-remote - update to 4.9.4-23.0.1
podman - update to 4.9.4-23.0.1
podman-catatonit - update to 4.9.4-23.0.1
podman-tests - update to 4.9.4-23.0.1
podman-gvproxy - update to 4.9.4-23.0.1
podman-docker - update to 4.9.4-23.0.1
podman-plugins - update to 4.9.4-23.0.1
podman-docker - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman-debuginfo - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podmansh - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman-remote - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
Red Hat OpenShift Container Platform - addressed in versions 4.12.84, 4.12.87, 4.13.62, 4.13.63, 4.14.61, 4.15.60, 4.15.61, 4.16.53, 4.16.55, 4.17.47, 4.18.29, 4.18.31
kernel (Red Hat package) - addressed in versions 4.18.0-372.175.1.el8_6, 5.14.0-284.153.1.el9_2, 5.14.0-284.154.1.el9_2, 5.14.0-284.155.1.el9_2, 5.14.0-427.105.1.el9_4, 5.14.0-427.107.1.el9_4
Arista CloudEOS VM - addressed in versions 4.32.9M, 4.34.5M, 4.35.3F
Arista Extensible Operating System (EOS) - addressed in versions 4.32.9M, 4.34.5M, 4.35.3F
kernel-rt (Red Hat package) - addressed in versions 5.14.0-284.153.1.rt14.438.el9_2, 5.14.0-284.154.1.rt14.439.el9_2, 5.14.0-284.155.1.rt14.440.el9_2
cockpit-podman - update to 84.1-1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins