Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/null is insufficient, allowing container escape when youki utilizes bind mounting the container's /dev/null as a file mask. This issue is fixed in version 0.5.7.
References
Configurations
History
No history.
Information
Published : 2025-11-06 00:15
Updated : 2025-11-10 18:13
NVD link : CVE-2025-62161
Mitre link : CVE-2025-62161
CVE.ORG link : CVE-2025-62161
JSON object : View
Products Affected
youki-dev
- youki
