Red Hat released multiple security advisories for RHEL 8.8 and RHEL 9 container tooling to remediate vulnerabilities in runc, buildah, podman, skopeo, and related packages. The most serious issues were three runc flaws—CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881—that can enable container escape or denial of service through masked path abuse, /dev/console mount race conditions, and arbitrary write gadgets using procfs write redirects. Red Hat rated several of the updates Important, including advisories affecting RHEL 9.0 SAP Solutions, RHEL 9.2 channels, RHEL 9.4 channels, and broader RHEL 9 package streams.
The updates also addressed additional bundled-component flaws, including CVE-2025-58183 in Go's archive/tar package, which can trigger unbounded memory allocation when parsing a GNU sparse map; CVE-2025-47913 in golang.org/x/crypto/ssh/agent, which can cause a panic; and CVE-2025-65637 in github.com/sirupsen/logrus, a denial-of-service issue. Fixed package versions published across the advisories include runc 1.2.9-1.el9_2.1, buildah 1.29.5-1.el9_2.2, buildah 1.33.13-2.el9_4.1, buildah 1.41.6-1.el9_7, and updated RHEL 9.0 SAP Solutions builds for buildah, crun, podman, runc, and skopeo; Red Hat also shipped a Moderate update for the container-tools:rhel8 module to fix the Go archive/tar and logrus issues.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-15, Red Hat published Important advisory RHSA-2026:8325 for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. The advisory updates buildah, crun, podman, runc, and skopeo to fix runc container escape flaws CVE-2025-31133, CVE-2025-52565, CVE-2025-52881, plus CVE-2025-58183, CVE-2025-47913, and CVE-2025-65637.
On 2026-03-30, Red Hat published Moderate advisory RHSA-2026:6191 for the container-tools:rhel8 module in RHEL 8.8 update channels. The update remediates CVE-2025-58183 and CVE-2025-65637 and ships updated container-related packages including podman, buildah, skopeo, and runc.
On 2026-03-12, Red Hat published Important advisory RHSA-2026:4532 for buildah in RHEL 9.2 channels. The update provides buildah 1.29.5-1.el9_2.2 and addresses CVE-2025-52881, CVE-2025-58183, CVE-2025-47913, and CVE-2025-65637.
On 2026-03-12, Red Hat published Important advisory RHSA-2026:4531 for runc in RHEL 9.2 channels. The update provides runc 1.2.9-1.el9_2.1 and fixes container escape flaws CVE-2025-31133, CVE-2025-52565, CVE-2025-52881, plus logrus DoS issue CVE-2025-65637.
On 2026-01-12, Red Hat published Important advisory RHSA-2026:0426 for buildah in RHEL 9.4 streams, including Extended Update Support, SAP Solutions, and Extended Life Cycle variants. The update delivers buildah 1.33.13-2.el9_4.1 and addresses CVE-2025-52881 and CVE-2025-58183.
On 2025-11-25, Red Hat published Important advisory RHSA-2025:22011 for buildah on Red Hat Enterprise Linux 9. The update provides buildah 1.41.6-1.el9_7 and fixes CVE-2025-52881 and CVE-2025-58183 across multiple RHEL 9 variants and architectures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.