CVE-2025-52565
HighAdvisory
Published 5 Nov 2025In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.006
- 45th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 289
- of 17,781 indexed, latest versions
- Container images
- 224
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
runc container escape with malicious config due to /dev/console mount and related races
Carried by container images the latest versions of 289 of 17,781 indexed charts deploy, on 224 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| runcdeb | 1.1.5+ds1-1+deb12u1 | no fix listed | 9 |
| github.com/ | v1.0.0-rc6.0.20190115182101-c1e454b2a1bf, v1.0.0-rc8, v1.0.0-rc8.0.20190926150303-84373aaa560b, v1.0.0-rc9+29 more | 1.2.8 | 215 |
- OSV records
- DEBIAN-CVE-2025-52565GHSA-qw9x-cqr3-wc7r
- Also known as
- GO-2025-4097
Charts affected
289 by stars
Container images carrying it
224 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| anonaddy/ | 957a95565166 | github.com/ | 1.2.8 | 1 |
| apache/ | 3bb13d14f64a | github.com/ | 1.2.8 | 1 |
| aquasec/ | 944a04445179 | github.com/ | 1.2.8 | 1 |
| aquasec/ | 973d0df16189 | github.com/ | 1.2.8 | 1 |
| artifacthub/ | 6596c8c4d955 | github.com/ | 1.2.8 | 1 |
| assistiot/ | c3adbab6a3e7 | github.com/ | 1.2.8 | 1 |
| assistiot/ | 6a107f224c34 | github.com/ | 1.2.8 | 1 |
| assistiot/ | 0d3e6d35f168 | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | ac64829e45b3 | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | b6e381ffd6ae | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | cb04e49e6eb1 | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | 15edb5643b73 | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | 78847062532a | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | 43a70df0e7c6 | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | 0f7c8ac484ac | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | 3bb1deeaf9d0 | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | 3e65a6b89e38 | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | 8f7161d8ce19 | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | cf93e2772250 | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | 59293f5206b7 | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | 7788b908dd0d | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | bf01d031ba8c | github.com/ | 1.2.8 | 1 |
| bitnamilegacy/ | dba59d740e13 | github.com/ | 1.2.8 | 1 |
| btcpayserver/ | e9585b68dc6b | github.com/ | 1.2.8 | 1 |
| datasaker/ | 08b52999f67b | github.com/ | 1.2.8 | 1 |
| deepflowce/ | 3d7ae561cf60 | github.com/ | 1.2.8 | 1 |
| devopstales/ | 75136aa7a26e | github.com/ | 1.2.8 | 1 |
| eclipseaerios/ | 0208743f315e | github.com/ | 1.2.8 | 1 |
| eqalpha/ | fd9351ce27a7 | github.com/ | 1.2.8 | 1 |
| galaxy/ | e50a890e24c9 | github.com/ | 1.2.8 | 1 |
| gitea/ | 6120b1165f3a | github.com/ | 1.2.8 | 1 |
| gitlab/ | fd7e5dfb9f30 | github.com/ | 1.2.8 | 1 |
| gocrane/ | a1400909118c | github.com/ | 1.2.8 | 1 |
| gocrane/ | 9ba6d11b2079 | github.com/ | 1.2.8 | 1 |
| goharbor/ | 451103a6c8d8 | github.com/ | 1.2.8 | 1 |
| goharbor/ | b9522c3f5056 | github.com/ | 1.2.8 | 1 |
| goharbor/ | dc5b882a7db4 | github.com/ | 1.2.8 | 1 |
| grafana/ | 3364714a2f64 | github.com/ | 1.2.8 | 1 |
| grafana/ | f6cbec9409be | github.com/ | 1.2.8 | 1 |
| grafana/ | 01a63f4e032c | github.com/ | 1.2.8 | 1 |
| grafana/ | 8c7256f412fe | github.com/ | 1.2.8 | 1 |
| grafana/ | c3dac4e26471 | github.com/ | 1.2.8 | 1 |
| hashicorp/ | 339b78b61750 | github.com/ | 1.2.8 | 1 |
| hashicorp/ | fb70bd9210ff | github.com/ | 1.2.8 | 1 |
| hashicorp/ | 97d521a27498 | github.com/ | 1.2.8 | 1 |
| helga09/ | a03657d97897 | github.com/ | 1.2.8 | 1 |
| hiversh/ | 0e36d98402bc | runc | no fix listed | 1 |
| hiversh/ | b5048c6342ce | runc | no fix listed | 1 |
| hiversh/ | 2fbf9f264498 | runc | no fix listed | 1 |
| hiversh/ | 4f43130f51e5 | runc | no fix listed | 1 |