REDHAT-BUG-2404708: High severity runc runc vulnerability
A flaw was found in runc. CVE-2025-52565 is very similar in concept and application toCVE-2025-31133, except that it exploits a flaw in /dev/console bind-mounts. When creating the /dev/console bind-mount (to /dev/pts/$n), if an attacker replaces /dev/pts/$n with a symlink then runc will bind-mount the symlink target over /dev/console.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2404708?
The severity of REDHAT-BUG-2404708 is classified as critical due to its potential to allow unauthorized access via a bind-mount vulnerability in runc.
How do I fix REDHAT-BUG-2404708?
To fix REDHAT-BUG-2404708, upgrade to the patched version of runc provided in the latest security updates.
What systems are affected by REDHAT-BUG-2404708?
REDHAT-BUG-2404708 affects systems running vulnerable versions of runc.
Can REDHAT-BUG-2404708 lead to privilege escalation?
Yes, exploiting REDHAT-BUG-2404708 can lead to privilege escalation by allowing an attacker to manipulate bind-mounted consoles.
When was REDHAT-BUG-2404708 discovered?
The vulnerability identified as REDHAT-BUG-2404708 was discovered in early 2025.