Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vf95-55w6-qmrf | youki container escape and denial of service due to arbitrary write gadgets and procfs write redirects |
Mon, 10 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Youki-dev
Youki-dev youki |
|
| CPEs | cpe:2.3:a:youki-dev:youki:*:*:*:*:*:rust:*:* | |
| Vendors & Products |
Youki-dev
Youki-dev youki |
|
| Metrics |
cvssV3_1
|
Thu, 06 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Youki Project
Youki Project youki |
|
| Vendors & Products |
Youki Project
Youki Project youki |
Wed, 05 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficiently strict write-target validation, and when combined with path substitution during pathname resolution, can allow writes to unintended procfs locations. While resolving a path component-by-component, a shared-mount race can substitute intermediate components and redirect the final target. This issue is fixed in version 0.5.7. | |
| Title | youki container escape and denial of service due to arbitrary write gadgets and procfs write redirects | |
| Weaknesses | CWE-363 CWE-61 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-06T16:54:15.942Z
Reserved: 2025-10-16T19:24:37.266Z
Link: CVE-2025-62596
Updated: 2025-11-06T16:54:13.521Z
Status : Analyzed
Published: 2025-11-06T00:15:37.817
Modified: 2025-11-10T17:58:27.753
Link: CVE-2025-62596
No data.
OpenCVE Enrichment
Updated: 2025-11-06T10:06:54Z
Github GHSA