CVE-2025-2713

NameCVE-2025-2713
DescriptionGoogle gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
golang-gvisor-gvisor (PTS)bookworm0.0~20221219.0-2vulnerable
sid, trixie0.0~20240729.0-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-gvisor-gvisorsource(unstable)0.0~20240729.0-1

Notes

Fixed by: https://github.com/google/gvisor/commit/586c38d70081b13b2ed494cef48e99b93956843e (release-20240325.0)

Search for package or bug name: Reporting problems