A flaw was found in runc. This attack is a more sophisticated variant of CVE-2019-16884, which was a flaw that allowed an attacker to trick runc into writing the LSM process labels for a container process into a dummy tmpfs file and thus not apply the correct LSM labels to the container process. The mitigation applied for CVE-2019-16884 was fairly limited and effectively only caused runc to verify that when we write LSM labels that those labels are actual procfs files.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:19927 https://access.redhat.com/errata/RHSA-2025:19927
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:20957 https://access.redhat.com/errata/RHSA-2025:20957
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:21220 https://access.redhat.com/errata/RHSA-2025:21220
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:21232 https://access.redhat.com/errata/RHSA-2025:21232
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2025:21633 https://access.redhat.com/errata/RHSA-2025:21633
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2025:21634 https://access.redhat.com/errata/RHSA-2025:21634
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:21702 https://access.redhat.com/errata/RHSA-2025:21702
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2025:21328 https://access.redhat.com/errata/RHSA-2025:21328
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:22012 https://access.redhat.com/errata/RHSA-2025:22012
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:22011 https://access.redhat.com/errata/RHSA-2025:22011
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2025:22030 https://access.redhat.com/errata/RHSA-2025:22030
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2025:21795 https://access.redhat.com/errata/RHSA-2025:21795
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:21824 https://access.redhat.com/errata/RHSA-2025:21824
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2025:22275 https://access.redhat.com/errata/RHSA-2025:22275
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:23543 https://access.redhat.com/errata/RHSA-2025:23543
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2025:23347 https://access.redhat.com/errata/RHSA-2025:23347
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2025:23113 https://access.redhat.com/errata/RHSA-2025:23113
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:0424 https://access.redhat.com/errata/RHSA-2026:0424
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:0426 https://access.redhat.com/errata/RHSA-2026:0426
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:0425 https://access.redhat.com/errata/RHSA-2026:0425
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2026:0315 https://access.redhat.com/errata/RHSA-2026:0315
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2026:0316 https://access.redhat.com/errata/RHSA-2026:0316
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2026:0331 https://access.redhat.com/errata/RHSA-2026:0331
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2026:0418 https://access.redhat.com/errata/RHSA-2026:0418
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2026:0701 https://access.redhat.com/errata/RHSA-2026:0701
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2026:0676 https://access.redhat.com/errata/RHSA-2026:0676
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2026:0995 https://access.redhat.com/errata/RHSA-2026:0995
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2026:1540 https://access.redhat.com/errata/RHSA-2026:1540