MEDIUM
Cri-o: cri-o path traversal in log handling functions allows arbitrary unmounting
Published Jan 28, 2025
6.6
MEDIUMCVSS 3.1
EPSS 0.24%
Description
A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
No data.
No data.
Red Hat OpenShift Container Platform 4.17
cri-o-0:1.30.10-3.rhaos4.17.gitd088fcf.el8
Fixed · RHSA-2025:1122
Red Hat OpenShift Container Platform 4
rhcos
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.17 | cri-o-0:1.30.10-3.rhaos4.17.gitd088fcf.el8 | Fixed | RHSA-2025:1122 |
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | n/a |
github.com/cri-o/cri-o
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/cri-o/cri-o | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://access.redhat.com/errata/RHSA-2025:1122 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-0750 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2339405 issue-trackingx_refsource_REDHATIssue Tracking
- https://github.com/advisories/GHSA-hp5j-2585-qx6g Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-0750
- https://www.cve.org/CVERecord?id=CVE-2025-0750
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:1122 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2025-0750 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2339405 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://github.com/advisories/GHSA-hp5j-2585-qx6g | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-0750 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-0750 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 28, 2025
Updated Nov 20, 2025
Reserved Jan 27, 2025
Link CVE-2025-0750
CISA Vulnrichment
GHSA-HP5J-2585-QX6G Updated Jan 28, 2025