{"id":"GHSA-j26p-6wx7-f3pw","summary":"Youki: If /proc and /sys in the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem.","details":"### Summary\nIf `/proc` and `/sys` in the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem.\n\n### Details\n\nFor security reasons, container creation should be prohibited if `/proc` or `/sys` in the rootfs is a symbolic link.\nI verified this behavior with `youki`.\nWhen `/proc` or `/sys` is a symbolic link, `runc` fails to create the container, whereas `youki` successfully creates it.\n\nThis is the fix related to this issue in `runc`.\n* https://github.com/opencontainers/runc/pull/3756\n* https://github.com/opencontainers/runc/pull/3773\n* https://github.com/opencontainers/runc/blob/main/libcontainer/rootfs_linux.go#L590\n* https://github.com/opencontainers/runc/blob/main/tests/integration/mask.bats#L60\n\n\n### Impact\n\nThe following advisory appears to be related to this vulnerability:\n* https://github.com/advisories/GHSA-vpvm-3wq2-2wvm\n* https://github.com/advisories/GHSA-fh74-hm69-rqjw","aliases":["CVE-2025-54867"],"modified":"2025-08-14T19:37:22Z","published":"2025-08-14T16:39:04Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-08-14T16:39:04Z","nvd_published_at":"2025-08-14T16:15:39Z","cwe_ids":["CWE-61"]},"references":[{"type":"WEB","url":"https://github.com/youki-dev/youki/security/advisories/GHSA-j26p-6wx7-f3pw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54867"},{"type":"WEB","url":"https://github.com/youki-dev/youki/commit/0d9b4f2aa5ceaf988f3eb568711d2acf0a4ace37"},{"type":"PACKAGE","url":"https://github.com/youki-dev/youki"},{"type":"WEB","url":"https://github.com/youki-dev/youki/releases/tag/v0.5.5"}],"affected":[{"package":{"name":"youki","ecosystem":"crates.io","purl":"pkg:cargo/youki"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.5.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-j26p-6wx7-f3pw/GHSA-j26p-6wx7-f3pw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}