CVE-2025-27612

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Mar 21, 2025
CWE ID 276

Summary

CVE-2025-27612 is a vulnerability affecting the libcontainer library prior to version 0.5.3. This library is used for container control. The issue lies in the tenant builder, which accepts a list of capabilities to be added to a tenant container. If these capabilities are already present in the main container's capabilities, they will be inherited by the tenant container, potentially leading to elevated privileges. This vulnerability is similar to CVE-2022-29162 and only impacts users who directly utilize libcontainer and the tenant builder.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share