UNIX symbolic link following in runc - CVE-2025-52881
Published: November 5, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a symlink following issue related to procfs write redirects. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Successful exploitation of this vulnerability may result in privilege escalation.
Affected software
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Fedora
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Containers Module
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Arista Extensible Operating System (EOS)
Arista CloudEOS VM
Red Hat OpenShift Builds
Automation Assets in IBM Cloud Pak for Integration (CP4I)
buildah
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
toolbox-tests
toolbox
udica
python-eventlet (Red Hat package)
docker-runc
slirp4netns
runc
runc (Red Hat package)
runc-debuginfo
runc-doc
oci-seccomp-bpf-hook
runc-app (Ubuntu package)
containernetworking-plugins
containernetworking-plugins (Red Hat package)
aardvark-dns
node-exporter
netavark
alloy-debuginfo
alloy
fuse-overlayfs
crun (Red Hat package)
crun
skopeo-tests
skopeo
skopeo (Red Hat package)
cri-o (Red Hat package)
buildah (Red Hat package)
cri-tools (Red Hat package)
buildah-tests
buildah
containers-common
conmon
conmon (Red Hat package)
haproxy (Red Hat package)
ignition (Red Hat package)
container-selinux
criu
crit
criu-devel
criu-libs
python3-criu
libslirp-devel
libslirp
podman (Red Hat package)
python3-podman
podman
podman-docker
podman-catatonit
podman-gvproxy
podman-tests
podman-remote
podman-plugins
podmansh
podman-remote-debuginfo
podman-debuginfo
openshift (Red Hat package)
ose-gcp-gcr-image-credential-provider (Red Hat package)
ose-aws-ecr-image-credential-provider (Red Hat package)
ose-azure-acr-image-credential-provider (Red Hat package)
openshift-clients (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
cockpit-podman
How to mitigate CVE-2025-52881
Red Hat OpenShift Builds - update to 1.6.2
buildah - addressed in versions 1.33.14, 1.37.8
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.17-sc2, 4.3.1
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
python-eventlet (Red Hat package) - update to 0.33.1-7.el9
docker-runc - update to 1.0.0 rc3-229
slirp4netns - update to 1.2.3-1
runc - addressed in versions 1.2.5-2, 1.2.8-1, 1.2.9-2
runc (Red Hat package) - addressed in versions 1.2.5-3.el9_6, 1.2.9-1.el9_0, 1.2.9-1.el9_2.1, 1.2.9-1.rhaos4.16.el8, 1.2.9-1.rhaos4.16.el9, 1.2.9-1.rhaos4.17.el8, 1.2.9-1.rhaos4.17.el9, 1.2.9-1.rhaos4.18.el8, 1.2.9-1.rhaos4.18.el9, 1.2.9-3.rhaos4.17.el8, 1.2.9-3.rhaos4.17.el9, 1.3.0-4.el9_7
runc - addressed in versions 1.2.7-16.67.1, 1.2.7-150000.80.1, 1.3.3-16.70.1, 1.3.3-150000.85.1
runc-debuginfo - addressed in versions 1.2.7-16.67.1, 1.2.7-150000.80.1, 1.3.3-16.70.1, 1.3.3-150000.85.1
runc-doc - update to 1.2.8-1
oci-seccomp-bpf-hook - update to 1.2.10-1
runc-app (Ubuntu package) - addressed in versions 1.3.3-0ubuntu1~22.04.2, 1.3.3-0ubuntu1~22.04.3, 1.3.3-0ubuntu1~24.04.2, 1.3.3-0ubuntu1~24.04.3, 1.3.3-0ubuntu1~25.04.2, 1.3.3-0ubuntu1~25.04.3, 1.3.3-0ubuntu1~25.10.2, 1.3.3-0ubuntu1~25.10.3
runc - update to 1.3.3-1.fc44
containernetworking-plugins - update to 1.4.0-6.0.1
containernetworking-plugins (Red Hat package) - update to 1.4.0-7.rhaos4.17.el8
containernetworking-plugins - addressed in versions 1.9.1-1.fc42, 1.9.1-1.fc43, 1.9.1-1.fc44, 1.9.1-1.fc45
aardvark-dns - update to 1.10.1-2.0.1
node-exporter - addressed in versions 1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42, 1.10.2-3.fc43
netavark - update to 1.10.3-1.0.1
alloy-debuginfo - update to 1.12.2-150700.15.15.1
alloy - update to 1.12.2-150700.15.15.1
fuse-overlayfs - update to 1.13-1.0.1
crun (Red Hat package) - update to 1.14.3-1.el9_0
crun - update to 1.14.3-2
skopeo-tests - addressed in versions 1.14.5-4.0.1, 1.14.5-5
skopeo - addressed in versions 1.14.5-4.0.1, 1.14.5-5
skopeo (Red Hat package) - addressed in versions 1.16.1-4.rhaos4.17.el8, 1.16.1-4.rhaos4.17.el9
cri-o (Red Hat package) - addressed in versions 1.25.5-32.rhaos4.12.git6120b13.el8, 1.29.13-11.rhaos4.16.git979a5e6.el8, 1.29.13-11.rhaos4.16.git979a5e6.el9, 1.30.14-8.rhaos4.17.gitfa27f6f.el8, 1.30.14-8.rhaos4.17.gitfa27f6f.el9, 1.31.13-3.rhaos4.18.gite0b87e5.el8, 1.31.13-3.rhaos4.18.gite0b87e5.el9
buildah (Red Hat package) - addressed in versions 1.29.5-1.el9_2.2, 1.33.12-3.rhaos4.17.el8, 1.33.12-3.rhaos4.17.el9, 1.39.5-1.el9_6, 1.39.5-1.el10_0, 1.41.6-1.el9_7, 1.41.6-1.el10_1
cri-tools (Red Hat package) - addressed in versions 1.30.0-8.el8, 1.30.0-8.el9
buildah-tests - addressed in versions 1.33.12-2, 1.33.13-1
buildah - addressed in versions 1.33.12-2, 1.33.13-1
buildah - addressed in versions 1.35.5-150300.8.46.1, 1.35.5-150400.3.53.1, 1.35.5-150500.3.45.1
containers-common - update to 1-82.0.1
conmon - update to 2.1.10-1
conmon (Red Hat package) - addressed in versions 2.1.12-8.rhaos4.17.el8, 2.1.12-8.rhaos4.17.el9
haproxy (Red Hat package) - update to 2.8.10-2.rhaos4.18.el9
ignition (Red Hat package) - update to 2.18.0-10.rhaos4.17.el9
container-selinux - update to 2.229.0-2
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
libslirp-devel - update to 4.4.0-2
libslirp - update to 4.4.0-2
podman (Red Hat package) - addressed in versions 4.4.1-22.el9_2.5, 4.9.4-19.el9_4.5, 4.9.4-19.rhaos4.16.el8, 4.9.4-20.rhaos4.16.el9, 5.2.2-6.rhaos4.18.el8, 5.2.2-12.rhaos4.17.el8, 5.2.2-12.rhaos4.17.el9, 5.2.2-14.rhaos4.18.el9, 5.4.0-14.el10_0, 5.4.0-15.el9_6, 5.6.0-6.el10_1, 5.6.0-7.el9_7
python3-podman - update to 4.9.0-3
podman - addressed in versions 4.9.4-23.0.1, 4.9.4-25.0.2
podman-docker - addressed in versions 4.9.4-23.0.1, 4.9.4-25.0.2
podman-catatonit - addressed in versions 4.9.4-23.0.1, 4.9.4-25.0.2
podman-gvproxy - addressed in versions 4.9.4-23.0.1, 4.9.4-25.0.2
podman-tests - addressed in versions 4.9.4-23.0.1, 4.9.4-25.0.2
podman-remote - addressed in versions 4.9.4-23.0.1, 4.9.4-25.0.2
podman-plugins - addressed in versions 4.9.4-23.0.1, 4.9.4-25.0.2
podmansh - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman-docker - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman-remote - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
podman-debuginfo - addressed in versions 4.9.5-150300.9.63.2, 4.9.5-150400.4.59.2, 4.9.5-150500.3.56.2
Red Hat OpenShift Container Platform - addressed in versions 4.12.84, 4.13.62, 4.13.63, 4.14.61, 4.15.60, 4.15.61, 4.16.53, 4.16.55, 4.17.47, 4.17.50, 4.18.29, 4.18.31
openshift (Red Hat package) - addressed in versions 4.17.0-202602172017.p2.g4e295fa.assembly.stream.el8, 4.17.0-202602172017.p2.g4e295fa.assembly.stream.el9
ose-gcp-gcr-image-credential-provider (Red Hat package) - addressed in versions 4.17.0-202602172042.p2.g8ce997d.assembly.stream.el8, 4.17.0-202602172042.p2.g8ce997d.assembly.stream.el9
ose-aws-ecr-image-credential-provider (Red Hat package) - addressed in versions 4.17.0-202602172042.p2.g144bace.assembly.stream.el8, 4.17.0-202602172042.p2.g144bace.assembly.stream.el9
ose-azure-acr-image-credential-provider (Red Hat package) - addressed in versions 4.17.0-202602172042.p2.g626ecd1.assembly.stream.el8, 4.17.0-202602172042.p2.g626ecd1.assembly.stream.el9
openshift-clients (Red Hat package) - addressed in versions 4.17.0-202602172042.p2.gd76df14.assembly.stream.el8, 4.17.0-202602172042.p2.gd76df14.assembly.stream.el9
kernel (Red Hat package) - addressed in versions 4.18.0-372.175.1.el8_6, 5.14.0-284.153.1.el9_2, 5.14.0-284.154.1.el9_2, 5.14.0-284.155.1.el9_2, 5.14.0-427.105.1.el9_4, 5.14.0-427.107.1.el9_4, 5.14.0-427.112.1.el9_4
Arista Extensible Operating System (EOS) - addressed in versions 4.32.9M, 4.34.5M, 4.35.3F
Arista CloudEOS VM - addressed in versions 4.32.9M, 4.34.5M, 4.35.3F
kernel-rt (Red Hat package) - addressed in versions 5.14.0-284.153.1.rt14.438.el9_2, 5.14.0-284.154.1.rt14.439.el9_2, 5.14.0-284.155.1.rt14.440.el9_2
cockpit-podman - update to 84.1-1
External References
Related Security Bulletins
- Multiple vulnerabilities in runc
- Ubuntu update for runc-app
- SUSE update for runc
- SUSE update for runc
- Fedora 44 update for runc
- Red Hat Enterprise Linux 9 update for runc
- Red Hat Enterprise Linux 9 update for runc
- SUSE update for runc
- SUSE update for buildah
- SUSE update for buildah
- SUSE update for buildah
- SUSE update for runc
- SUSE update for podman
- SUSE update for podman
- SUSE update for podman
- Red Hat Enterprise Linux 10 update for podman
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Anolis OS update for container-tools:an8 module
- Red Hat Enterprise Linux 10 update for buildah
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for podman
- Anolis OS update for runc
- SUSE update for runc
- Ubuntu update for runc-app
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 10 update for buildah
- Red Hat Enterprise Linux 9 update for podman
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- openEuler update for runc
- Red Hat Enterprise Linux 10 update for podman
- Anolis OS update for container-tools:an8 module
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Builds 1.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Red Hat Enterprise Linux 9 update for podman
- buildah 1.37 update for third-party components
- buildah 1.33 update for third-party components
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13 packages
- SUSE update for alloy
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14 packages
- Fedora 43 update for node-exporter
- Fedora 42 update for node-exporter
- Fedora EPEL 10.2 update for node-exporter
- Fedora EPEL 10.1 update for node-exporter
- Fedora EPEL 9 update for node-exporter
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15 packages
- Red Hat Enterprise Linux 9 update for runc
- Red Hat Enterprise Linux 9 update for buildah
- Multiple vulnerabilities in Automation Assets in IBM Cloud Pak for Integration (CP4I)
- Red Hat Enterprise Linux 9 update for podman
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17 packages
- Fedora 45 update for containernetworking-plugins
- Fedora 44 update for containernetworking-plugins
- Fedora 43 update for containernetworking-plugins
- Fedora 42 update for containernetworking-plugins
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Arista EOS update for runc
- Red Hat Enterprise Linux 9 update for multiple packages