If you're using (edit: pretty much any, including k8s, docker, containerd) containers: congrats! You get to patch three new runc vulnerabilities that could allow for a full container break-out.
CVE-2025-31133: symlink attack on bind-mount of /dev/null for masked paths
https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2
CVE-2025-52565: same as above, but for /dev/console / /dev/pts/$n
https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r
CVE-2025-52881: rehash of CVE-2019-19921, writing LSM labels into a dummy tmpfs
https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm