• CVE-2025-24965

发布时间: 2025年4月11日

修改时间: 2025年4月11日

概要

crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into escaping the root filesystem, allowing file creation or modification on the host. No special permissions are needed, only the ability for the current user to write to the target file. The problem is fixed in crun 1.20 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Network
CVSS评分 N/A 8.7
Attack Complexity Low
Privileges Required Low
Scope Changed
Integrity High
User Interaction Required
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2476 crun security update 2025年5月1日

影响产品

产品 状态
V6 crun Fixed