Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fj4-9m67-3mj3

Опубликовано: 28 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.8
CVSS3: 7.8

Описание

Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.

Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.

EPSS

Процентиль: 0%
0.00007
Низкий

6.8 Medium

CVSS4

7.8 High

CVSS3

Дефекты

CWE-266
CWE-269

Связанные уязвимости

CVSS3: 7.8
ubuntu
11 месяцев назад

Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.

CVSS3: 7.8
nvd
11 месяцев назад

Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.

CVSS3: 7.8
debian
11 месяцев назад

Google gVisor's runsc component exhibited a local privilege escalation ...

EPSS

Процентиль: 0%
0.00007
Низкий

6.8 Medium

CVSS4

7.8 High

CVSS3

Дефекты

CWE-266
CWE-269