PT-2025-45167 · Youki · Youki

Published

2025-11-05

·

Updated

2025-11-11

·

CVE-2025-62596

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Youki versions 0.5.6 and below
Description Youki, a container runtime written in Rust, has an issue with its apparmor handling. Insufficiently strict write-target validation, combined with path substitution during pathname resolution, can allow writes to unintended procfs locations. A shared-mount race can substitute intermediate path components, redirecting the final target during path resolution.
Recommendations Update to Youki version 0.5.7 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2025-62596
GHSA-VF95-55W6-QMRF

Affected Products

Youki