CVE-2025-57848: Red Hat Openshift Virtualization 4

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.

Affected products

  • Red Hat Red Hat Openshift Virtualization 4
  • Red Hat Rhel-8-Cnv-4.12: before v4.12.21-4 (fixed in v4.12.21-4); before v4.12.21-3 (fixed in v4.12.21-3); before v4.12.21-21 (fixed in v4.12.21-21); before v4.12.21-5 (fixed in v4.12.21-5); before v4.12.21-9 (fixed in v4.12.21-9); before v4.12.21-8 (fixed in v4.12.21-8)
  • Red Hat Rhel-9-Cnv-4.14: before v4.14.16-6 (fixed in v4.14.16-6); before v4.14.16-8 (fixed in v4.14.16-8); before v4.14.16-3 (fixed in v4.14.16-3); before v4.14.16.rhel9-46 (fixed in v4.14.16.rhel9-46); before v4.14.16-7 (fixed in v4.14.16-7); before v4.14.16-53 (fixed in v4.14.16-53); …
  • Red Hat Rhel-9-Cnv-4.17: before v4.17.34-1 (fixed in v4.17.34-1); before v4.17.34.rhel9-16 (fixed in v4.17.34.rhel9-16); before v4.17.34-2 (fixed in v4.17.34-2); before v4.17.34-20 (fixed in v4.17.34-20); before v4.17.34-19 (fixed in v4.17.34-19); before v4.17.34-4 (fixed in v4.17.34-4)
  • Red Hat Rhel-9-Cnv-4.18: before v4.18.22-1 (fixed in v4.18.22-1); before v4.18.22.rhel9-8 (fixed in v4.18.22.rhel9-8); before v4.18.22-8 (fixed in v4.18.22-8); before v4.18.22-2 (fixed in v4.18.22-2)
  • Red Hat Rhel-9-Cnv-4.19: before v4.19.14-1 (fixed in v4.19.14-1); before v4.19.14.rhel9-6 (fixed in v4.19.14.rhel9-6); before v4.19.14-7 (fixed in v4.19.14-7); before v4.19.14-2 (fixed in v4.19.14-2); before v4.19.14-6 (fixed in v4.19.14-6)

Published 2025-10-23. Last modified 2026-10-08.