CVE-2025-31160
LOWatop < 2.11.0 - Denial of Service via Unprivileged Process Execution
Title source: llmDescription
atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or possibly have unspecified other impact by running certain types of unprivileged processes while a different user runs atop.
References (11)
Core 11
Core References
Various Sources
https://blog.bismuth.sh/blog/bismuth-found-the-atop-bug
Various Sources
https://news.ycombinator.com/item?id=43477057
Various Sources
https://news.ycombinator.com/item?id=43485980
Various Sources
https://rachelbythebay.com/w/2025/03/26/atop/
Scores
CVSS v3
2.9
EPSS
0.0016
EPSS Percentile
5.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-617
Status
published
Products (1)
atop project/atop
< 2.11.0
Published
Mar 26, 2025
Tracked Since
Feb 18, 2026