Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-4437

Опубликовано: 26 июн. 2025
Источник: redhat
CVSS3: 5.7

Описание

There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire /etc/passwd file into memory. If this file is excessively large, it can cause the a high memory consumption leading applications to be killed due to out-of-memory. As a result a denial-of-service can be achieved, possibly disrupting other pods and services running in the same host.

Отчет

This vulnerability was rated as Moderate by the Red Hat's Product Security team as it requires the attacker to own an account with minimal privileges to create pods using the CRI-O utility.

Меры по смягчению последствий

As for now there's no available mitigation for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4cri-oFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2375084cri-o: Large /etc/passwd file may lead to Denial of Service

5.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
nvd
4 месяца назад

There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire /etc/passwd file into memory. If this file is excessively large, it can cause the a high memory consumption leading applications to be killed due to out-of-memory. As a result a denial-of-service can be achieved, possibly disrupting other pods and services running in the same host.

CVSS3: 5.7
debian
4 месяца назад

There's a vulnerability in the CRI-O application where when container ...

CVSS3: 5.7
github
4 месяца назад

CRI-O has Potential High Memory Consumption from File Read

5.7 Medium

CVSS3