Container Privilege Escalation Vulnerability in Container-native Virtualization by Red Hat
CVE-2025-57848
5.2MEDIUM
What is CVE-2025-57848?
A vulnerability exists in certain Container-native Virtualization images due to permissive group-writable settings on the /etc/passwd file during construction. Under specific circumstances, an attacker with command execution capability within an affected container, even without root access, may exploit their inclusion in the root group to alter the /etc/passwd file. This manipulation could enable the attacker to introduce a new user with an arbitrary UID, including UID 0. Such an action could grant the attacker full root privileges inside the container, presenting significant security risks.
References
CVSS V3.1
Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Antony Di Scala and Mike Whale for reporting this issue.