CVE-2025-24965

Name
CVE-2025-24965
Description
crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into escaping the root filesystem, allowing file creation or modification on the host. No special permissions are needed, only the ability for the current user to write to the target file. The problem is fixed in crun 1.20 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/containers/crun/commit/0aec82c2b686f0b1793deed43b46524fe2e8b5a7
MISC https://github.com/containers/crun/releases/tag/1.20
CONFIRM https://github.com/containers/crun/security/advisories/GHSA-f42g-r5jj-qh4j

Match rules

CPE URI Source package Min version Max version
crun >= 0 < 1.20

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
crun edge-community 1.20-r0 Michał Polański <michal@polanski.me> fixed
crun 3.21-community 1.20-r0 Michał Polański <michal@polanski.me> fixed