Criu develops checkpoint/restore in userspace, a container and process serialization utility used in containerized environments and live-migration scenarios where sensitive runtime state must be preserved and reconstructed. The durable signal in its vulnerability profile centers on information-disclosure weaknesses tied to the handling of process memory and credentials during checkpoint and restore operations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Criu over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-5228HIGH The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing files via unspecified vectors re | Jun 7, 2016 | 7.8 | 20 | NO | NO |
CVE-2015-5231MEDIUM The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace | Jun 7, 2016 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Criu.
Media articles that mention a CVE ID that affects a product developed by Criu — matched by CVE ID, not by vendor name.