CVE-2015-5228: Criu Checkpoint/restore In Userspace

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing files via unspecified vectors related to a directory path.

Affected products

  • Criu Checkpoint/restore In Userspace: affected versions not specified
  • Opensuse Opensuse: version 13.2 only

Published 2016-06-07. Last modified 2026-06-17.