CVE-2025-24965

HIGH

crun <1.20 - Privilege Escalation

Title source: llm
STIX 2.1

Description

crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into escaping the root filesystem, allowing file creation or modification on the host. No special permissions are needed, only the ability for the current user to write to the target file. The problem is fixed in crun 1.20 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Scores

CVSS v4 8.5
EPSS 0.0022
EPSS Percentile 44.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
containers/crun < 1.20
Published Feb 19, 2025
Tracked Since Feb 18, 2026