CVE-2025-24965 - CVE House
Back to Database
Status published High CVE-2025-24965

.krun_config.json symlink attack creates or overwrites file on the host in crun

Vulnerability Description

crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into escaping the root filesystem, allowing file creation or modification on the host. No special permissions are needed, only the ability for the current user to write to the target file. The problem is fixed in crun 1.20 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-24965

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

crun
Vulnerable Versions:
< 1.20

Timeline

Official Publish: February 19th, 2025
Last Modified: February 19th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)