CVE-2025-52881

HIGH

runc <1.4.0-rc.2 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-52881. PoCs published by jq6l43d1.

AI-analyzed exploit summary This repository provides a detailed technical analysis and workaround for CVE-2025-52881, which involves an AppArmor incompatibility issue in Proxmox LXC containers running recent versions of runc. The solution includes scripts to automatically apply and manage AppArmor configuration changes to resolve Docker and container runtime failures.

Description

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.

Exploits (1)

nomisec WRITEUP 15 stars
by jq6l43d1 · poc
https://github.com/jq6l43d1/proxmox-lxc-docker-fix

This repository provides a detailed technical analysis and workaround for CVE-2025-52881, which involves an AppArmor incompatibility issue in Proxmox LXC containers running recent versions of runc. The solution includes scripts to automatically apply and manage AppArmor configuration changes to resolve Docker and container runtime failures.

Classification
Writeup 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Proxmox VE with LXC containers running runc 1.2.7+/1.3.2+
Auth required
Prerequisites: Proxmox VE host with LXC containers · Docker or other container runtimes installed in LXC · runc versions 1.2.7+ or 1.3.2+
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (20)

Core 20
Core References
Exploit, Mitigation, Patch, Third Party Advisory x_refsource_confirm
https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm

Scores

CVSS v3 7.5
EPSS 0.0002
EPSS Percentile 3.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-61 CWE-363
Status published
Products (4)
linuxfoundation/runc 1.4.0 rc1 (2 CPE variants)
linuxfoundation/runc < 1.2.8
opencontainers/runc 0 - 1.2.8Go
opencontainers/selinux 0 - 1.13.0Go
Published Nov 06, 2025
Tracked Since Feb 18, 2026