{"id":"GHSA-vf95-55w6-qmrf","summary":"youki container escape and denial of service due to arbitrary write gadgets and procfs write redirects","details":"### Impact ###\n\nyouki’s apparmor handling performs insufficiently strict write-target validation, which—combined with path substitution during pathname resolution—can allow writes to unintended procfs locations.\n\n**Weak write-target check**\nyouki only verifies that the destination lies somewhere under procfs. As a result, a write intended for `/proc/self/attr/apparmor/exec` can succeed even if the path has been redirected to `/proc/sys/kernel/hostname`(which is also in procfs).\n\n**Path substitution**\nWhile resolving a path component-by-component, a shared-mount race can substitute intermediate components and redirect the final target.\n\nThis is a different project, but the core logic is similar to the CVE in runc. Issues were identified in runc, and verification was also conducted in youki to confirm the problems.\nhttps://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm\n\n### Credits ###\n\nThanks to Li Fubang (@lifubang from acmcoder.com, CIIC) and Tõnis Tiigi (@tonistiigi from Docker) for both independently discovering runc's original vulnerability, as well as Aleksa Sarai (@cyphar from SUSE) for the original research into this class of security issues and solutions.","aliases":["CVE-2025-62596"],"modified":"2025-11-15T02:25:28Z","published":"2025-11-05T18:45:18Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-11-05T18:45:18Z","nvd_published_at":"2025-11-06T00:15:37Z","cwe_ids":["CWE-363","CWE-61"]},"references":[{"type":"WEB","url":"https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm"},{"type":"WEB","url":"https://github.com/youki-dev/youki/security/advisories/GHSA-vf95-55w6-qmrf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62596"},{"type":"WEB","url":"https://github.com/youki-dev/youki/commit/5886c91073b9be748bd8d5aed49c4a820548030a"},{"type":"PACKAGE","url":"https://github.com/youki-dev/youki"},{"type":"WEB","url":"https://pkg.go.dev/github.com/cyphar/filepath-securejoin/pathrs-lite/procfs"},{"type":"WEB","url":"https://youtu.be/tGseJW_uBB8"},{"type":"WEB","url":"https://youtu.be/y1PaBzxwRWQ"}],"affected":[{"package":{"name":"youki","ecosystem":"crates.io","purl":"pkg:cargo/youki"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.5.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-vf95-55w6-qmrf/GHSA-vf95-55w6-qmrf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}