The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing files via unspecified vectors related to a directory path.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade criu | Jul 30, 2024 | Jun 7, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 25, 2015 |
| Suse | — | Upgrade criu-debugsourceUpgrade libcriu1-debuginfoUpgrade criuUpgrade criu-debuginfoUpgrade libcriu1Upgrade criu-devel | Dec 18, 2015 | Sep 22, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub