CVE-2025-0750 describes a path traversal vulnerability in CRI-O's log management functions. An attacker with permissions to create and delete Pods could exploit this to unmount arbitrary host paths, potentially causing a node-level denial of service by unmounting critical system directories. This vulnerability has a CVSS score of 6.6 (Medium), indicating a local attack vector with low complexity and high impact on availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | Range not provided by sourceCNA affecteddefault affected | |
| Https://Github.Com/Cri-O/Cri-O | Cri-O | >= 0, < 1.33.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.