Some Docker containers might not be as secure as they’d like, experts warn


  • Three runC flaws could allow container escape and host access with administrator privileges
  • Bugs affect Docker/Kubernetes setups using custom mounts and older versions of RunC
  • Mitigation includes user namespaces and rootless containers to limit the impact of exploits.

The runC container runtime, used in both Docker and Kubernetes, had three high-severity vulnerabilities that could be used to access the underlying system, security researchers warned.

Security researcher Aleksa Sarai revealed that she discovered CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881, three bugs that, when chained together, granted access to the underlying container host with administrator privileges.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top