Home

Description

Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/null is insufficient, allowing container escape when youki utilizes bind mounting the container's /dev/null as a file mask. This issue is fixed in version 0.5.7.

PUBLISHED Reserved 2025-10-07 | Published 2025-11-05 | Updated 2025-11-06 | Assigner GitHub_M




HIGH: 7.3CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-363: Race Condition Enabling Link Following

CWE-61: UNIX Symbolic Link (Symlink) Following

Product status

< 0.5.7
affected

References

github.com/.../youki/security/advisories/GHSA-4g74-7cff-xcv8

github.com/.../youki/security/advisories/GHSA-4g74-7cff-xcv8

github.com/...ommit/5886c91073b9be748bd8d5aed49c4a820548030a

cve.org (CVE-2025-62161)

nvd.nist.gov (CVE-2025-62161)

Download JSON