The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade criu | Jul 30, 2024 | Jun 7, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 25, 2015 |
| Suse | — | Upgrade criu-debugsourceUpgrade criu-develUpgrade libcriu1-debuginfoUpgrade criu-debuginfoUpgrade libcriu1Upgrade criu | Dec 18, 2015 | Sep 22, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub