home.social

#runc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #runc, aggregated by home.social.

fetched live
  1. Beyond performance, runc 1.5.0-rc.3 is a heads-up to anyone building on libcontainer: the cmsg helpers move to internal packages and several libcontainer/devices symbols are deprecated, all scheduled for removal in runc 1.6, with compatibility wrappers until then. With the final 1.5.0 expected within two weeks, downstream runtimes have a short window to adjust. Who still builds directly against libcontainer in 2026?
    #runc #Kubernetes

  2. Beyond performance, runc 1.5.0-rc.3 is a heads-up to anyone building on libcontainer: the cmsg helpers move to internal packages and several libcontainer/devices symbols are deprecated, all scheduled for removal in runc 1.6, with compatibility wrappers until then. With the final 1.5.0 expected within two weeks, downstream runtimes have a short window to adjust. Who still builds directly against libcontainer in 2026?
    #runc #Kubernetes

  3. runc 1.5.0-rc.3 landed as the third and likely final candidate before 1.5.0, expected within two weeks. The headline change reuses a single non-writable tmpfs when masking directories, cutting the number of tmpfs superblocks cleaned up on teardown, which helps dense Kubernetes hosts. It also fixes runc list handling of a missing --root and deprecates the cmsg helpers and some libcontainer/devices symbols before removal in 1.6. Are you pinning runc or tracking rc builds?
    #runc #containers

  4. runc 1.5.0-rc.3 landed as the third and likely final candidate before 1.5.0, expected within two weeks. The headline change reuses a single non-writable tmpfs when masking directories, cutting the number of tmpfs superblocks cleaned up on teardown, which helps dense Kubernetes hosts. It also fixes runc list handling of a missing --root and deprecates the cmsg helpers and some libcontainer/devices symbols before removal in 1.6. Are you pinning runc or tracking rc builds?
    #runc #containers

  5. 🚨 All channels include critical fixes for runc vulnerabilities -
    CVE-2025-31133, CVE-2025-52565, CVE-2025-52881. Update soon to stay safe!
    #Flatcar #Security #runc

  6. 🚨 All channels include critical fixes for runc vulnerabilities -
    CVE-2025-31133, CVE-2025-52565, CVE-2025-52881. Update soon to stay safe!
    #Flatcar #Security #runc

  7. 🚨 All channels include critical fixes for runc vulnerabilities -
    CVE-2025-31133, CVE-2025-52565, CVE-2025-52881. Update soon to stay safe!

  8. 🚨 All channels include critical fixes for runc vulnerabilities -
    CVE-2025-31133, CVE-2025-52565, CVE-2025-52881. Update soon to stay safe!
    #Flatcar #Security #runc

  9. 🚨 All channels include critical fixes for runc vulnerabilities -
    CVE-2025-31133, CVE-2025-52565, CVE-2025-52881. Update soon to stay safe!
    #Flatcar #Security #runc

  10. Alert: Three critical runC vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) enable mount/symlink-based escapes that may redirect writes to /proc or other host targets. A successful exploit requires container start privileges via crafted mounts or malicious images/Dockerfiles. Patches: runC 1.2.8 / 1.3.3 / 1.4.0-rc.3+.
    Detection & mitigation guidance:
    • Patch runC immediately.
    • Deploy rootless containers and enable user namespaces without host root mapping.
    • Monitor for rapid symlink creation, unexpected bind mounts of /dev/null or /dev/console, and anomalous writes to procfs entries (e.g., /proc/sysrq-trigger).
    • Harden CI/CD image provenance checks and disallow unverified custom mount configurations.
    Share any YARA/OSQuery/Suricata rules you’ve validated — let’s collate detection patterns. Follow TechNadu for vetted technical advisories.

    #containersecurity #runC #CVE #Kubernetes #Docker #threathunting #DFIR #DevSecOps

  11. Alert: Three critical runC vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) enable mount/symlink-based escapes that may redirect writes to /proc or other host targets. A successful exploit requires container start privileges via crafted mounts or malicious images/Dockerfiles. Patches: runC 1.2.8 / 1.3.3 / 1.4.0-rc.3+.
    Detection & mitigation guidance:
    • Patch runC immediately.
    • Deploy rootless containers and enable user namespaces without host root mapping.
    • Monitor for rapid symlink creation, unexpected bind mounts of /dev/null or /dev/console, and anomalous writes to procfs entries (e.g., /proc/sysrq-trigger).
    • Harden CI/CD image provenance checks and disallow unverified custom mount configurations.
    Share any YARA/OSQuery/Suricata rules you’ve validated — let’s collate detection patterns. Follow TechNadu for vetted technical advisories.

    #containersecurity #runC #CVE #Kubernetes #Docker #threathunting #DFIR #DevSecOps

  12. Alert: Three critical runC vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) enable mount/symlink-based escapes that may redirect writes to /proc or other host targets. A successful exploit requires container start privileges via crafted mounts or malicious images/Dockerfiles. Patches: runC 1.2.8 / 1.3.3 / 1.4.0-rc.3+.
    Detection & mitigation guidance:
    • Patch runC immediately.
    • Deploy rootless containers and enable user namespaces without host root mapping.
    • Monitor for rapid symlink creation, unexpected bind mounts of /dev/null or /dev/console, and anomalous writes to procfs entries (e.g., /proc/sysrq-trigger).
    • Harden CI/CD image provenance checks and disallow unverified custom mount configurations.
    Share any YARA/OSQuery/Suricata rules you’ve validated — let’s collate detection patterns. Follow TechNadu for vetted technical advisories.

    #containersecurity #runC #CVE #Kubernetes #Docker #threathunting #DFIR #DevSecOps

  13. Alert: Three critical runC vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) enable mount/symlink-based escapes that may redirect writes to /proc or other host targets. A successful exploit requires container start privileges via crafted mounts or malicious images/Dockerfiles. Patches: runC 1.2.8 / 1.3.3 / 1.4.0-rc.3+.
    Detection & mitigation guidance:
    • Patch runC immediately.
    • Deploy rootless containers and enable user namespaces without host root mapping.
    • Monitor for rapid symlink creation, unexpected bind mounts of /dev/null or /dev/console, and anomalous writes to procfs entries (e.g., /proc/sysrq-trigger).
    • Harden CI/CD image provenance checks and disallow unverified custom mount configurations.
    Share any YARA/OSQuery/Suricata rules you’ve validated — let’s collate detection patterns. Follow TechNadu for vetted technical advisories.

    #containersecurity #runC #CVE #Kubernetes #Docker #threathunting #DFIR #DevSecOps

  14. Alert: Three critical runC vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) enable mount/symlink-based escapes that may redirect writes to /proc or other host targets. A successful exploit requires container start privileges via crafted mounts or malicious images/Dockerfiles. Patches: runC 1.2.8 / 1.3.3 / 1.4.0-rc.3+.
    Detection & mitigation guidance:
    • Patch runC immediately.
    • Deploy rootless containers and enable user namespaces without host root mapping.
    • Monitor for rapid symlink creation, unexpected bind mounts of /dev/null or /dev/console, and anomalous writes to procfs entries (e.g., /proc/sysrq-trigger).
    • Harden CI/CD image provenance checks and disallow unverified custom mount configurations.
    Share any YARA/OSQuery/Suricata rules you’ve validated — let’s collate detection patterns. Follow TechNadu for vetted technical advisories.

    #containersecurity #runC #CVE #Kubernetes #Docker #threathunting #DFIR #DevSecOps

  15. #Kubernetes: Newly disclosed #vulnerabilities in the #runC container runtime used in #Docker & Kubernetes (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) could be exploited to bypass isolation restrictions & get access to the host system (escape):
    #k8s

    bleepingcomputer.com/news/secu

  16. #Kubernetes: Newly disclosed #vulnerabilities in the #runC container runtime used in #Docker & Kubernetes (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) could be exploited to bypass isolation restrictions & get access to the host system (escape):
    #k8s

    bleepingcomputer.com/news/secu

  17. #Kubernetes: Newly disclosed #vulnerabilities in the #runC container runtime used in #Docker & Kubernetes (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) could be exploited to bypass isolation restrictions & get access to the host system (escape):
    #k8s

    bleepingcomputer.com/news/secu

  18. #Kubernetes: Newly disclosed #vulnerabilities in the #runC container runtime used in #Docker & Kubernetes (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) could be exploited to bypass isolation restrictions & get access to the host system (escape):
    #k8s

    bleepingcomputer.com/news/secu

  19. #Kubernetes: Newly disclosed #vulnerabilities in the #runC container runtime used in #Docker & Kubernetes (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) could be exploited to bypass isolation restrictions & get access to the host system (escape):
    #k8s

    bleepingcomputer.com/news/secu

  20. Внутреннее устройство Docker. Заглянем под капот

    Сначала были физические серверы - дорогие и неэффективные. Затем пришли виртуальные машины , которые позволили запускать несколько изолированных ОС на одном железе. Но цена изоляции оставалась высокой: полная копия ОС, гигабайты диска, минуты на запуск. Контейнеры - следующий шаг эволюции. Зачем виртуализировать целое железо и запускать полноценную ОС, если можно изолировать только сам процесс , используя встроенные механизмы ядра? Этот подход на порядок легче, быстрее и эффективнее.

    habr.com/ru/articles/963702/

    #docker #containerd #runc #linux #containers #container #контейнеризация #докер #devops #линукс

  21. Внутреннее устройство Docker. Заглянем под капот

    Сначала были физические серверы - дорогие и неэффективные. Затем пришли виртуальные машины , которые позволили запускать несколько изолированных ОС на одном железе. Но цена изоляции оставалась высокой: полная копия ОС, гигабайты диска, минуты на запуск. Контейнеры - следующий шаг эволюции. Зачем виртуализировать целое железо и запускать полноценную ОС, если можно изолировать только сам процесс , используя встроенные механизмы ядра? Этот подход на порядок легче, быстрее и эффективнее.

    habr.com/ru/articles/963702/

    #docker #containerd #runc #linux #containers #container #контейнеризация #докер #devops #линукс

  22. Внутреннее устройство Docker. Заглянем под капот

    Сначала были физические серверы - дорогие и неэффективные. Затем пришли виртуальные машины , которые позволили запускать несколько изолированных ОС на одном железе. Но цена изоляции оставалась высокой: полная копия ОС, гигабайты диска, минуты на запуск. Контейнеры - следующий шаг эволюции. Зачем виртуализировать целое железо и запускать полноценную ОС, если можно изолировать только сам процесс , используя встроенные механизмы ядра? Этот подход на порядок легче, быстрее и эффективнее.

    habr.com/ru/articles/963702/

    #docker #containerd #runc #linux #containers #container #контейнеризация #докер #devops #линукс

  23. If you use runc for your underlying container runtime (the default in many environments including Docker and many Kubernetes installs), there's a security update that just came out today. github.com/opencontainers/runc
    #runc #docker #kubernetes #containers

  24. If you use runc for your underlying container runtime (the default in many environments including Docker and many Kubernetes installs), there's a security update that just came out today. github.com/opencontainers/runc

  25. If you use runc for your underlying container runtime (the default in many environments including Docker and many Kubernetes installs), there's a security update that just came out today. github.com/opencontainers/runc
    #runc #docker #kubernetes #containers

  26. If you use runc for your underlying container runtime (the default in many environments including Docker and many Kubernetes installs), there's a security update that just came out today. github.com/opencontainers/runc
    #runc #docker #kubernetes #containers

  27. If you use runc for your underlying container runtime (the default in many environments including Docker and many Kubernetes installs), there's a security update that just came out today. github.com/opencontainers/runc
    #runc #docker #kubernetes #containers

  28. Docker изнутри: исчерпывающее руководство. Механизмы контейнеризации + примеры, эксперименты и реализация

    Docker — не магия, а грамотное применение механизмов Linux. Разбираем инструмент, который пугает своей сложностью не меньше блокчейна. Показываем на пальцах как работают: Namespaces, Cgroups, OverlayFS – основные компоненты любого контейнера, и как стандарт OCI объединяет их в единую экосистему. Об этом и не только в статье.

    habr.com/ru/articles/935178/

    #docker #контейнеризация #namespaces #cgroups #linux_kernel #виртуализация #runc #golang #linux

  29. Docker изнутри: исчерпывающее руководство. Механизмы контейнеризации + примеры, эксперименты и реализация

    Docker — не магия, а грамотное применение механизмов Linux. Разбираем инструмент, который пугает своей сложностью не меньше блокчейна. Показываем на пальцах как работают: Namespaces, Cgroups, OverlayFS – основные компоненты любого контейнера, и как стандарт OCI объединяет их в единую экосистему. Об этом и не только в статье.

    habr.com/ru/articles/935178/

    #docker #контейнеризация #namespaces #cgroups #linux_kernel #виртуализация #runc #golang #linux

  30. Docker изнутри: исчерпывающее руководство. Механизмы контейнеризации + примеры, эксперименты и реализация

    Docker — не магия, а грамотное применение механизмов Linux. Разбираем инструмент, который пугает своей сложностью не меньше блокчейна. Показываем на пальцах как работают: Namespaces, Cgroups, OverlayFS – основные компоненты любого контейнера, и как стандарт OCI объединяет их в единую экосистему. Об этом и не только в статье.

    habr.com/ru/articles/935178/

    #docker #контейнеризация #namespaces #cgroups #linux_kernel #виртуализация #runc #golang #linux

  31. 🏗️ Supports distributable workers, multiple output formats & pluggable architecture for maximum flexibility
    🔒 Execution without root privileges using #runc or #crun backends with #containerd worker support

  32. 🏗️ Supports distributable workers, multiple output formats & pluggable architecture for maximum flexibility
    🔒 Execution without root privileges using #runc or #crun backends with #containerd worker support

  33. 🏗️ Supports distributable workers, multiple output formats & pluggable architecture for maximum flexibility
    🔒 Execution without root privileges using #runc or #crun backends with #containerd worker support

  34. 🏗️ Supports distributable workers, multiple output formats & pluggable architecture for maximum flexibility
    🔒 Execution without root privileges using #runc or #crun backends with #containerd worker support

  35. 🏗️ Supports distributable workers, multiple output formats & pluggable architecture for maximum flexibility
    🔒 Execution without root privileges using #runc or #crun backends with #containerd worker support