Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.
History

Fri, 28 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 15:45:00 +0000

Type Values Removed Values Added
Description Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.
Title Improper File Permission Handling in Google gVisor runsc
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published: 2025-03-28T15:27:43.231Z

Updated: 2025-03-28T16:14:47.370Z

Reserved: 2025-03-24T11:35:56.590Z

Link: CVE-2025-2713

cve-icon Vulnrichment

Updated: 2025-03-28T16:14:32.921Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-28T16:15:30.043

Modified: 2025-03-28T18:11:40.180

Link: CVE-2025-2713

cve-icon Redhat

No data.