Container escape via "masked path" abuse due to mount race conditions in github.com/opencontainers/runc
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2025-4096" }
{ "imports": [ { "path": "github.com/opencontainers/runc/libcontainer" } ] }
"https://vuln.go.dev/ID/GO-2025-4096.json"