Youki: If /proc and /sys in the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem.
Description
Published by the National Vulnerability Database
Aug 14, 2025
Published to the GitHub Advisory Database
Aug 14, 2025
Reviewed
Aug 14, 2025
Last updated
Aug 14, 2025
Summary
If
/procand/sysin the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem.Details
For security reasons, container creation should be prohibited if
/procor/sysin the rootfs is a symbolic link.I verified this behavior with
youki.When
/procor/sysis a symbolic link,runcfails to create the container, whereasyoukisuccessfully creates it.This is the fix related to this issue in
runc.Impact
The following advisory appears to be related to this vulnerability:
References