PT-2025-4037 · Cri-O+1 · Cri-O+1

·

CVE-2025-0750

·

Published

2025-01-28

·

Updated

2025-02-11

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions CRI-O (affected versions not specified)
Description A path traversal issue in the log management functions, specifically UnMountPodLogs and LinkContainerLogs, may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths. This could lead to node-level denial of service by unmounting critical system directories.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-0750
GHSA-HP5J-2585-QX6G
GO-2025-3426
OPENSUSE-SU-2025:14728-1
OPENSUSE-SU-2025_0429-1
RHSA-2025:1122
SUSE-SU-2025:0429-1

Affected Products

Cri-O
Suse