StackRadar

CVE-2025-52565

High

Advisory

Published 5 Nov 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
289
of 17,781 indexed, latest versions
Container images
224
deployed by those charts
Fix available
1 of 2
affected packages

runc container escape with malicious config due to /dev/console mount and related races

Carried by container images the latest versions of 289 of 17,781 indexed charts deploy, on 224 images.

Affected packageAffected versionsFixed inImages
runcdeb1.1.5+ds1-1+deb12u1no fix listed9
github.com/opencontainers/runcgolangv1.0.0-rc6.0.20190115182101-c1e454b2a1bf, v1.0.0-rc8, v1.0.0-rc8.0.20190926150303-84373aaa560b, v1.0.0-rc9+29 more1.2.8215
OSV records
DEBIAN-CVE-2025-52565GHSA-qw9x-cqr3-wc7r
Also known as
GO-2025-4097

Charts affected

289 by stars
ChartLatestAffected imagesRadar Score
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
github.com/opencontainers/runc@v1.0.0-rc9
1.2.8

Open the chart page →

15,291
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
github.com/opencontainers/runc@v1.0.0-rc9
1.2.8

Open the chart page →

15,291
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
github.com/opencontainers/runc@v1.0.0-rc91.0.20200707015106-819fcc687efb
1.2.8

Open the chart page →

11,437
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/opencontainers/runc@v1.1.10
1.2.8

Open the chart page →

16,047
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/opencontainers/runc@v1.0.0-rc9
1.2.8

Open the chart page →

29,227
redisredis-arm17.8.01 of 1See more

redis redis-arm 17.8.0

1 of the 1 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
ghcr.io/zcube/bitnami-compat/redis:7.0-debian-11-r55118a403046f7
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

1,906
olivetinrm3lVerified publisher0.2.01 of 1See more

olivetin rm3l 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
ghcr.io/olivetin/olivetin:2025.2.19a89958921526
github.com/opencontainers/runc@v1.2.4
1.2.8

Open the chart page →

1,370
gitlab-operatorrock8sVerified publisher0.7.01 of 2See more

gitlab-operator rock8s 0.7.0

1 of the 2 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
github.com/opencontainers/runc@v1.0.2
1.2.8

Open the chart page →

5,422
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/opencontainers/runc@v1.1.5
1.2.8
quay.io/devtron/postgres:14.91b594392f7cb
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

68,240
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
quay.io/devtron/postgres:14.91b594392f7cb
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

32,902
routehub-serverroutehub-helm1.0.11 of 3See more

routehub-server routehub-helm 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
github.com/opencontainers/runc@v1.0.1
1.2.8

Open the chart page →

6,890
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

12,668
opentelemetry-collectorsb-helm-charts0.3.01 of 1See more

opentelemetry-collector sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/opencontainers/runc@v1.1.12
1.2.8

Open the chart page →

1,721
searchpesearchpe4.1.01 of 2See more

searchpe searchpe 4.1.0

1 of the 2 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
library/postgres:13.703652c675ae1
github.com/opencontainers/runc@v1.0.1
1.2.8

Open the chart page →

2,637
backendsignalen4.24.02 of 4See more

backend signalen 4.24.0

2 of the 4 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
github.com/opencontainers/runc@v1.0.1
1.2.8
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
github.com/opencontainers/runc@v1.0.1
1.2.8

Open the chart page →

11,636
trilliansigstoreVerified publisher0.3.171 of 5See more

trillian sigstore 0.3.17

1 of the 5 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

2,808
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
github.com/opencontainers/runc@v1.1.12
1.2.8

Open the chart page →

2,429
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
github.com/opencontainers/runc@v1.1.2
1.2.8

Open the chart page →

3,462
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
helga09/my_sql_shoes:v1.1.1a03657d97897
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

7,574
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/opencontainers/runc@v1.1.5
1.2.8

Open the chart page →

7,672
redissoftonic0.3.01 of 2See more

redis softonic 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
library/redis:5.0fc5ecd863862
github.com/opencontainers/runc@v1.0.1
1.2.8

Open the chart page →

1,731
redis-high-availabilitysomeblackmagic1.3.101 of 3See more

redis-high-availability someblackmagic 1.3.10

1 of the 3 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.8-debian-11-r0bf01d031ba8c
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

3,148
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

66,266
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/opencontainers/runc@v1.0.0-rc91
1.2.8

Open the chart page →

28,165
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

13,646
ingress-nginx-external-lbsuminhong1.0.01 of 2See more

ingress-nginx-external-lb suminhong 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
github.com/opencontainers/runc@v1.1.12
1.2.8

Open the chart page →

2,094
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

12,655
ingress-nginxsvtech-public-helm-charts1.0.01 of 1See more

ingress-nginx svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
github.com/opencontainers/runc@v1.1.9
1.2.8

Open the chart page →

1,480
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

5,841
explorersynapse0.2.162 of 6See more

explorer synapse 0.2.16

2 of the 6 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
yandex/clickhouse-server:latest1cbf75aabe1e
github.com/opencontainers/runc@v1.0.1
1.2.8
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/opencontainers/runc@v1.1.5
1.2.8

Open the chart page →

8,518
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
github.com/opencontainers/runc@v1.1.7
1.2.8

Open the chart page →

4,212
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

17,461
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
library/mongo:5.0.217c81758cb295
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

20,270
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
pysga1996/redis:latest3af6d0c7db19
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

4,661
steamcmdthetredevVerified publisher1.0.91 of 1See more

steamcmd thetredev 1.0.9

1 of the 1 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
ghcr.io/thetredev/steamcmd:srcds-20240309dbb0f042cb31
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

1,075
phonebook-chartusuladams2Verified publisher0.2.11 of 3See more

phonebook-chart usuladams2 0.2.1

1 of the 3 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

3,176
wallarm-ingress-rcwallarmVerified publisher4.8.41 of 2See more

wallarm-ingress-rc wallarm 4.8.4

1 of the 2 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
wallarm/ingress-controller:4.8.0-1a591b9c91570
github.com/opencontainers/runc@v1.1.7
1.2.8

Open the chart page →

2,635
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
github.com/opencontainers/runc@v1.1.0
1.2.8

Open the chart page →

9,248
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2025-52565.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/opencontainers/runc@v1.1.5
1.2.8

Open the chart page →

2,022

Container images carrying it

224 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/opencontainers/runc@v1.0.0-rc91
1.2.8
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
github.com/opencontainers/runc@v1.1.5
1.2.8
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
github.com/opencontainers/runc@v1.0.0-rc9
1.2.8
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/opencontainers/runc@v1.1.5
1.2.8
1
quay.io/openshift/origin-cli:4.66722d5041b47
github.com/opencontainers/runc@v1.0.0-rc91.0.20200707015106-819fcc687efb
1.2.8
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
github.com/opencontainers/runc@v1.0.0-rc8.0.20190926150303-84373aaa560b
1.2.8
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/opencontainers/runc@v1.1.10
1.2.8
1
quay.io/operator-framework/olm1b6002156f56
github.com/opencontainers/runc@v1.1.12
1.2.8
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/opencontainers/runc@v1.0.1
1.2.8
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/opencontainers/runc@v1.0.0-rc9
1.2.8
1
quay.io/skopeo/stable:v1.134853591bd1d2
github.com/opencontainers/runc@v1.1.7
1.2.8
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
github.com/opencontainers/runc@v1.0.2
1.2.8
1
registry.k8s.io/csi-vsphere/driver:v3.4.0f5349a8ae3f3
github.com/opencontainers/runc@v1.1.13
1.2.8
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
github.com/opencontainers/runc@v1.1.4
1.2.8
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
github.com/opencontainers/runc@v1.1.12
1.2.8
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
github.com/opencontainers/runc@v1.1.4
1.2.8
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
github.com/opencontainers/runc@v1.1.2
1.2.8
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
github.com/opencontainers/runc@v1.1.7
1.2.8
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
github.com/opencontainers/runc@v1.1.4
1.2.8
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
github.com/opencontainers/runc@v1.1.3
1.2.8
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
github.com/opencontainers/runc@v1.1.14
1.2.8
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
github.com/opencontainers/runc@v1.1.12
1.2.8
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
github.com/opencontainers/runc@v1.2.3
1.2.8
1
registry.k8s.io/nfd/node-feature-discovery:v0.16.619ebca8b3804
github.com/opencontainers/runc@v1.1.14
1.2.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.