CVE-2025-57848: Container-native-virtualization: privilege escalation via excessive /etc/passwd permissions
A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.
Security readout for executives and security teams
Plain-English summary
Affected Red Hat Container-native Virtualization images may let an already-privileged container user become root inside that container. The weakness comes from unsafe permissions on /etc/passwd. It does not establish a direct remote compromise or host escape, but root access could significantly increase damage within a compromised workload.
Executive priority
Treat this as a planned, near-term remediation for affected CNV 4.12 environments, with faster action where users or processes can execute commands inside containers. The prerequisites reduce immediate likelihood, but successful escalation grants root within the container and can materially increase the impact of an existing compromise.
Technical view
During image creation, /etc/passwd is group-writable. Under specific conditions, a non-root command-capable user belonging to the root group can alter that file, create an account assigned UID 0, and gain container-root privileges. CVSS 3.1 is 6.4, reflecting local access, high complexity, high required privileges, and high confidentiality, integrity, and availability impacts.
Likely exposure
Exposure is limited to the listed RHEL-8-CNV-4.12 image packages and versions, including networking, storage, operator, console, must-gather, and Tekton task components. Prioritize containers where non-root users can execute commands and retain root-group membership. The bundle does not identify other products or versions as affected.
Exploitation context
The attack requires existing command execution inside an affected container, root-group membership, high privileges, and specific conditions. The bundle marks the CVE as absent from KEV and provides no evidence of active exploitation. It also does not demonstrate host-level container escape.
Researcher notes
CWE-276 applies because default file permissions are excessive. Assessment should distinguish image build-time state from runtime changes and verify effective group membership. Evidence supports container-local UID 0 escalation only; host escape, cross-container impact, public proof-of-concept availability, and active exploitation are not established by the supplied sources.
Mitigation direction
Inventory deployments using the listed RHEL-8-CNV-4.12 image packages and versions.
Review the applicable Red Hat CVE entry and errata for vendor-approved updates.
Apply applicable Red Hat updates using established change-control and rollback procedures.
Restrict unnecessary container command access and root-group membership pending remediation.
Replace affected running containers after updating their source images.
Validation and detection
Confirm deployed image package names and versions against the affected list.
Inspect affected containers to verify /etc/passwd is not group-writable.
Verify non-root runtime identities do not unnecessarily belong to the root group.
Confirm updated images follow the applicable Red Hat errata guidance.
Recreate containers and verify the intended updated image digest is running.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-276: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
The affected technology mentions containers, so container-specific ATT&CK technique review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
5Timeline events
1ADP providers
8Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.