UNIX symbolic link following in runc - CVE-2025-31133
Published: November 5, 2025 / Updated: April 10, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a symlink following issue within the maskedPaths feature. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Successful exploitation of this vulnerability may result in privilege escalation.
Affected software
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Containers Module
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Fedora
Arista CloudEOS VM
Arista Extensible Operating System (EOS)
buildah
Red Hat OpenShift Container Platform
Maximo Application Suite - IoT Component
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
toolbox-tests
toolbox
udica
python-eventlet (Red Hat package)
docker-runc
slirp4netns
runc
runc (Red Hat package)
runc-debuginfo
runc-doc
oci-seccomp-bpf-hook
runc-app (Ubuntu package)
containernetworking-plugins
aardvark-dns
netavark
alloy-debuginfo
alloy
fuse-overlayfs
crun (Red Hat package)
crun
skopeo
skopeo-tests
cri-o (Red Hat package)
buildah-tests
buildah
containers-common
conmon
haproxy (Red Hat package)
container-selinux
criu-devel
criu-libs
python3-criu
criu
crit
libslirp
libslirp-devel
python3-podman
podman (Red Hat package)
podman-remote
podman
podman-catatonit
podman-tests
podman-gvproxy
podman-docker
podman-plugins
podman-debuginfo
podmansh
podman-remote-debuginfo
kernel (Red Hat package)
kernel-rt (Red Hat package)
cockpit-podman
How to mitigate CVE-2025-31133
buildah - update to 1.33.14
Maximo Application Suite - IoT Component - addressed in versions 8.7.29, 8.8.25, 9.0.15, 9.1.6
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
python-eventlet (Red Hat package) - update to 0.33.1-7.el9
docker-runc - update to 1.0.0 rc3-229
slirp4netns - update to 1.2.3-1
runc - addressed in versions 1.2.5-2, 1.2.8-1
runc (Red Hat package) - addressed in versions 1.2.5-3.el9_6, 1.2.9-1.el9_0, 1.2.9-1.el9_2.1, 1.2.9-1.rhaos4.16.el8, 1.2.9-1.rhaos4.16.el9, 1.2.9-1.rhaos4.17.el8, 1.2.9-1.rhaos4.17.el9, 1.2.9-1.rhaos4.18.el8, 1.2.9-1.rhaos4.18.el9, 1.3.0-4.el9_7
runc - addressed in versions 1.2.7-16.67.1, 1.2.7-150000.80.1, 1.3.3-16.70.1, 1.3.3-150000.85.1
runc-debuginfo - addressed in versions 1.2.7-16.67.1, 1.2.7-150000.80.1, 1.3.3-16.70.1, 1.3.3-150000.85.1
runc-doc - update to 1.2.8-1
oci-seccomp-bpf-hook - update to 1.2.10-1
runc-app (Ubuntu package) - addressed in versions 1.3.3-0ubuntu1~22.04.2, 1.3.3-0ubuntu1~22.04.3, 1.3.3-0ubuntu1~24.04.2, 1.3.3-0ubuntu1~24.04.3, 1.3.3-0ubuntu1~25.04.2, 1.3.3-0ubuntu1~25.04.3, 1.3.3-0ubuntu1~25.10.2, 1.3.3-0ubuntu1~25.10.3
runc - update to 1.3.3-1.fc44
containernetworking-plugins - update to 1.4.0-6.0.1
aardvark-dns - update to 1.10.1-2.0.1
netavark - update to 1.10.3-1.0.1
alloy-debuginfo - update to 1.12.2-150700.15.15.1
alloy - update to 1.12.2-150700.15.15.1
fuse-overlayfs - update to 1.13-1.0.1
crun (Red Hat package) - update to 1.14.3-1.el9_0
crun - update to 1.14.3-2
skopeo - update to 1.14.5-4.0.1
skopeo-tests - update to 1.14.5-4.0.1
cri-o (Red Hat package) - addressed in versions 1.25.5-32.rhaos4.12.git6120b13.el8, 1.29.13-11.rhaos4.16.git979a5e6.el8, 1.29.13-11.rhaos4.16.git979a5e6.el9, 1.31.13-3.rhaos4.18.gite0b87e5.el8, 1.31.13-3.rhaos4.18.gite0b87e5.el9
buildah-tests - update to 1.33.12-2
buildah - update to 1.33.12-2
containers-common - update to 1-82.0.1
conmon - update to 2.1.10-1
haproxy (Red Hat package) - update to 2.8.10-2.rhaos4.18.el9
container-selinux - update to 2.229.0-2
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
python3-podman - update to 4.9.0-3
podman (Red Hat package) - addressed in versions 4.9.4-19.rhaos4.16.el8, 4.9.4-20.rhaos4.16.el9, 5.2.2-6.rhaos4.18.el8, 5.2.2-12.rhaos4.17.el8, 5.2.2-12.rhaos4.17.el9, 5.2.2-14.rhaos4.18.el9
podman-remote - update to 4.9.4-23.0.1
podman - update to 4.9.4-23.0.1
podman-catatonit - update to 4.9.4-23.0.1
podman-tests - update to 4.9.4-23.0.1
podman-gvproxy - update to 4.9.4-23.0.1
podman-docker - update to 4.9.4-23.0.1
podman-plugins - update to 4.9.4-23.0.1
podman-docker - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman-debuginfo - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podmansh - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman-remote - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
Red Hat OpenShift Container Platform - addressed in versions 4.12.84, 4.12.87, 4.13.62, 4.13.63, 4.14.61, 4.15.60, 4.15.61, 4.16.53, 4.16.55, 4.17.47, 4.18.29, 4.18.31
kernel (Red Hat package) - addressed in versions 4.18.0-372.175.1.el8_6, 5.14.0-284.153.1.el9_2, 5.14.0-284.154.1.el9_2, 5.14.0-284.155.1.el9_2, 5.14.0-427.105.1.el9_4, 5.14.0-427.107.1.el9_4
Arista CloudEOS VM - addressed in versions 4.32.9M, 4.34.5M, 4.35.3F
Arista Extensible Operating System (EOS) - addressed in versions 4.32.9M, 4.34.5M, 4.35.3F
kernel-rt (Red Hat package) - addressed in versions 5.14.0-284.153.1.rt14.438.el9_2, 5.14.0-284.154.1.rt14.439.el9_2, 5.14.0-284.155.1.rt14.440.el9_2
cockpit-podman - update to 84.1-1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in runc
- Ubuntu update for runc-app
- SUSE update for runc
- SUSE update for runc
- Fedora 44 update for runc
- Red Hat Enterprise Linux 9 update for runc
- Red Hat Enterprise Linux 9 update for runc
- SUSE update for runc
- SUSE update for runc
- SUSE update for podman
- SUSE update for podman
- SUSE update for podman
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Anolis OS update for container-tools:an8 module
- Anolis OS update for runc
- SUSE update for runc
- Ubuntu update for runc-app
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- openEuler update for runc
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- buildah 1.33 update for third-party components
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13 packages
- SUSE update for alloy
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15 packages
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Red Hat Enterprise Linux 9 update for runc
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Arista EOS update for runc
- Red Hat Enterprise Linux 9 update for multiple packages