Back

MEDIUM

Cri-o: cri-o path traversal in log handling functions allows arbitrary unmounting

Published Jan 28, 2025

Description

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 28, 2025
Updated Nov 20, 2025
Reserved Jan 27, 2025
CISA Vulnrichment
Updated Jan 28, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 22, 2025
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a
GHSA-HP5J-2585-QX6G