CVE-2025-2713 Details
Description
Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.
A local privilege escalation vulnerability has been identified in the runsc component of Google gVisor. This issue arises from improper management of file access permissions, enabling unprivileged users to reach restricted files. The vulnerability occurs because the process operates with root-like permissions until the first fork.
Users can update to the latest version of Google gVisor, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/google/gvisor/commit/586c38d70081b13b2ed494cef48e99b93956843e | [email protected] | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| google gvisor | < 20240325.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 26, 2025 | Modified Analysis | [email protected] |
| Sep 8, 2025 | CVE Modified | [email protected] |
| Aug 1, 2025 | Initial Analysis | [email protected] |
| Mar 28, 2025 | New CVE Received | [email protected] |