VYPR
Unrated severityNVD Advisory· Published Mar 28, 2025· Updated Sep 8, 2025

Improper File Permission Handling in Google gVisor runsc

CVE-2025-2713

Description

Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.

Affected products

2
  • Google/gVisorllm-create
  • Google/gVisorv5
    Range: release-20250319.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.