Red Hat released a broad set of Important security updates for RHEL, OpenShift Container Platform, and container tooling to fix three runc vulnerabilities that can enable container escape: CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881. The flaws affect runc directly and propagate into packages and platforms built around it, including podman, buildah, skopeo, and OpenShift releases spanning 4.12 through 4.18, as well as RHEL 8, RHEL 9, and selected RHEL 10 channels. Red Hat also shipped related fixes in some advisories for additional bundled issues such as CVE-2025-58183 in Go archive/tar, CVE-2025-65637 in logrus, and CVE-2025-22871 in Go net/http.
Bug records describe CVE-2025-31133 as a masked-path mount race that can abuse /dev/null, CVE-2025-52565 as a /dev/console bind-mount race involving symlink replacement, and CVE-2025-52881 as a higher-severity opencontainers/selinux flaw that can cause container escape and denial of service through arbitrary write gadgets and procfs write redirects. Red Hat said the issues were addressed through updated runc and container-stack packages, including releases such as runc 1.2.9-1.el9_4, runc 1.2.5-3.el9_6, runc 1.3.0-4.el9_7, and updated OpenShift builds and images, and urged customers to upgrade affected systems through standard RHEL update channels or OpenShift release channels.

See real exploitation activity before you spend the cycle.
24 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-27, Red Hat published RHSA-2026:10703 for the container-tools:rhel8 module on RHEL 8.6 support channels, fixing the three runc vulnerabilities along with CVE-2025-58183, CVE-2025-47913, and CVE-2025-65637.
On 2026-03-17, Red Hat published RHSA-2026:4693 for the container-tools:rhel8 module on RHEL 8.8 channels, updating podman, buildah, skopeo, and runc to fix six vulnerabilities including the three runc flaws.
On 2026-03-12, Red Hat issued RHSA-2026:4533 for podman in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related channels, fixing CVE-2025-52881, CVE-2025-58183, and CVE-2025-65637.
On 2026-02-05, Red Hat issued RHSA-2026:1540 for OpenShift Container Platform 4.15.61, updating packages and images to remediate CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.
On 2026-01-30, Red Hat published RHSA-2026:0995 for OpenShift Container Platform 4.14.61, providing updated packages that fix CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.
On 2026-01-22, Red Hat issued RHSA-2026:0701 for OpenShift Container Platform 4.17.47, releasing updated RPM packages to address the three runc-related vulnerabilities.
On 2026-01-22, Red Hat published RHSA-2026:0676 for OpenShift Container Platform 4.13.63, updating packages and images to fix CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.
On 2026-01-15, Red Hat issued RHSA-2026:0418 for OpenShift Container Platform 4.16.55, providing updated runc, cri-o, and podman packages to remediate CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.
On 2026-01-15, Red Hat published RHSA-2026:0331 for OpenShift Container Platform 4.18.31, updating packages and images to fix the three runc-related vulnerabilities.
On 2026-01-15, Red Hat issued RHSA-2026:0315 for OpenShift Container Platform 4.12.84, shipping updated packages and images that address CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.
On 2026-01-12, Red Hat published RHSA-2026:0425 for runc in Red Hat Enterprise Linux 9.4 Extended Update Support and related channels, fixing the three runc flaws plus CVE-2025-65637 in logrus.
On 2025-12-18, Red Hat updated advisory RHSA-2025:23347 after its initial release for the RHEL 10.0 EUS podman security update.
On 2025-12-17, Red Hat published RHSA-2025:23543, an Important security advisory for the container-tools:rhel8 module on Red Hat Enterprise Linux 8 and Extended Life Cycle 8.10 variants. The update fixes CVE-2025-52881 in runc and ships updated container-tools packages including podman, buildah, skopeo, and runc.
On 2025-12-16, Red Hat issued RHSA-2025:23347 for podman on Red Hat Enterprise Linux 10.0 Extended Update Support, fixing CVE-2025-52881 and CVE-2025-58183 with podman 5.4.0-14.el10_0.
On 2025-11-25, Red Hat published RHSA-2025:22030 for podman on RHEL 9.6 Extended Update Support and related channels, fixing CVE-2025-52881 and CVE-2025-58183.
On 2025-11-20, Red Hat published RHSA-2025:21328 for OpenShift Container Platform 4.14.59, providing updated packages that fix CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.
On 2025-11-18, Red Hat issued RHSA-2025:21633, an Important security advisory for buildah on Red Hat Enterprise Linux 10.0 channels. The update shipped buildah 1.39.5-1.el10_0 across RHEL 10.0 variants to address CVE-2025-52881, a runc container escape and denial-of-service flaw.
On 2025-11-13, Red Hat published RHSA-2025:21232 for the container-tools:rhel8 module on Red Hat Enterprise Linux 8, updating podman, buildah, skopeo, and runc to address the three runc flaws.
On 2025-11-11, Red Hat issued RHSA-2025:20957 for Red Hat Enterprise Linux 9 with runc 1.3.0-4.el9_7, again fixing CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881 across RHEL 9 variants.
On 2025-11-07, Red Hat published RHSA-2025:19927 for Red Hat Enterprise Linux 9, releasing updated runc packages to fix CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.
On 2025-11-05, Red Hat published its CVE-2025-52881 entry describing an Important-severity runc flaw that can enable container escape and denial of service through arbitrary write gadgets and procfs write redirects. Red Hat characterized it as a more sophisticated variant of CVE-2019-16884 and recommended rootless containers as a mitigation.
On 2025-11-05, Red Hat published its CVE-2025-31133 entry describing an Important-severity runc masked-path handling flaw that can enable container escape, and included severity scoring and mitigation guidance such as user namespaces, avoiding root in containers, and AppArmor protections.
On 2026-06-01, Red Hat updated RHSA-2026:0701 after its initial publication for OpenShift Container Platform 4.17.47.
Red Hat released OpenShift Container Platform 4.15.60 as a security and bug-fix update that remediated CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881 alongside other flaws.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
27 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.