Container Privilege Escalation Vulnerability in Container-native Virtualization by Red Hat
CVE-2025-57848
What is CVE-2025-57848?
A vulnerability exists in certain Container-native Virtualization images due to permissive group-writable settings on the /etc/passwd file during construction. Under specific circumstances, an attacker with command execution capability within an affected container, even without root access, may exploit their inclusion in the root group to alter the /etc/passwd file. This manipulation could enable the attacker to introduce a new user with an arbitrary UID, including UID 0. Such an action could grant the attacker full root privileges inside the container, presenting significant security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved