CVE-2025-2713

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
28/03/2025
Last modified:
26/09/2025

Description

Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:gvisor:*:*:*:*:*:*:*:* 20240325.0 (excluding)