CVE-2025-57849
published 2026-03-13CVE-2025-57849: A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable…
PriorityP336medium6.4CVSS 3.1
AVLACHPRHUINSUCHIHAH
EPSS
0.21%
11.0th percentile
A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | fuse | — | — |
CVSS provenance
nvdv3.16.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
fuse: privilege escalation via excessive /etc/passwd permissions
vendor_redhat·2026-03-13·CVSS 6.4
CVE-2025-57849 [MEDIUM] CWE-276 fuse: privilege escalation via excessive /etc/passwd permissions
fuse: privilege escalation via excessive /etc/passwd permissions
A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.
A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker
GHSA
GHSA-wf9w-74ph-2gqq: A container privilege escalation flaw was found in certain Fuse images
ghsa_unreviewed·2026-03-13
CVE-2025-57849 [MEDIUM] CWE-276 GHSA-wf9w-74ph-2gqq: A container privilege escalation flaw was found in certain Fuse images
A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-13
Published