Container Privilege Escalation Vulnerability in Container-native Virtualization by Red Hat
CVE-2025-57848

5.2MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
23 October 2025

What is CVE-2025-57848?

A vulnerability exists in certain Container-native Virtualization images due to permissive group-writable settings on the /etc/passwd file during construction. Under specific circumstances, an attacker with command execution capability within an affected container, even without root access, may exploit their inclusion in the root group to alter the /etc/passwd file. This manipulation could enable the attacker to introduce a new user with an arbitrary UID, including UID 0. Such an action could grant the attacker full root privileges inside the container, presenting significant security risks.

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Antony Di Scala and Mike Whale for reporting this issue.
.
CVE-2025-57848 : Container Privilege Escalation Vulnerability in Container-native Virtualization by Red Hat