CVE-2025-0750

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.
Configurations

No configuration.

History

11 Feb 2025, 12:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:1122 -
Summary
  • (es) Se encontró una vulnerabilidad en CRI-O. Un problema de Path Traversal en las funciones de administración de registros (UnMountPodLogs y LinkContainerLogs) puede permitir que un atacante con permisos para crear y eliminar Pods desmonte rutas de host arbitrarias, lo que genera una denegación de servicio a nivel de nodo al desmontar directorios sistema críticos.

28 Jan 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-28 10:15

Updated : 2025-02-11 12:15


NVD link : CVE-2025-0750

Mitre link : CVE-2025-0750

CVE.ORG link : CVE-2025-0750


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')