Home / Security / Advisories / NTAP-20251121-0003
NTAP-20251121-0003 — CVE-2025-52881 Runc Vulnerability in NetApp Products
Published 2025-11-21 · Updated 2026-09-24 · Status: Interim · Exploitation: Public · Severity: HIGH 7.5 · ONTAP affected: Yes
Product family: Astra Control · NetApp Console / BlueXP · ONTAP · SolidFire / NetApp HCI | ONTAP-relevant | highest CVSS: 7.5
CVEs in this advisory
- CVE-2025-52881 — HIGH · CVSS 7.5 · site index
What the CVE records say
CVE-2025-52881 — runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3.
Impact
Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).
Affected products
- Astra Control Center
- NetApp Console Agent
- ONTAP tools for VMware vSphere 10
- NetApp Console Agent Container (cadvisor)
- NetApp Console Agent Container (prometheus)
- NetApp Console Agent OVA
- NetApp SolidFire & HCI Management Node
- NetApp SolidFire & HCI Storage Node (Element Software)
Official fixes
- ONTAP tools for VMware vSphere 10 — vendor fix ↗
- NetApp Console Agent — vendor fix ↗
References
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2025