CVE-2025-27612Incorrect Default Permissions in Youki

Severity
5.9MEDIUMNVD
EPSS
0.1%
top 75.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMar 25

Description

libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the tenant builder accepts a list of capabilities to be added in the spec of tenant container. The logic here adds the given capabilities to all capabilities of main container if present in spec, otherwise simply set provided capabilities as capabilities of the tenant container. However, setting inherited caps in any case for tenant container can lead to elevation of capabilities, sim

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 2.5 | Impact: 3.4

Affected Packages2 packages

crates.iodocker/libcontainer< 0.5.3
CVEListV5youki-dev/youki< 0.5.3

🔴Vulnerability Details

4
OSV
WITHDRAWN: Libcontainer is affected by capabilities elevation in github.com/opencontainers/runc2025-03-25
CVEList
Libcontainer is affected by capabilities elevation2025-03-21
GHSA
Libcontainer is affected by capabilities elevation similar to GHSA-f3fp-gc8g-vw662025-03-21
OSV
Libcontainer is affected by capabilities elevation similar to GHSA-f3fp-gc8g-vw662025-03-21

📋Vendor Advisories

1
Red Hat
libcontainer: Libcontainer is affected by capabilities elevation2025-03-21
CVE-2025-27612 — Incorrect Default Permissions in Youki | cvebase