PT-2025-12424 · Unknown · Libcontainer
Published
2022-05-24
·
Updated
2025-03-28
·
CVE-2025-27612
CVSS v3.1
5.9
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
libcontainer versions prior to 0.5.3
Description
The issue arises when creating a tenant container using libcontainer, where the tenant builder accepts a list of capabilities to be added to the spec of the tenant container. This logic can lead to the elevation of capabilities if inherited caps are set for the tenant container. The problem is specific to direct usage of libcontainer and its tenant builder, and does not affect the youki binary itself.
Recommendations
For libcontainer versions prior to 0.5.3, update to version 0.5.3 or later to resolve the issue.
Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libcontainer