CVE-2025-57854
CVE-2025-57854 is a medium-severity vulnerability in Redhat Openshift Update Service with a CVSS 3.x base score of 6.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-276.
Key facts
- Severity: Medium (CVSS 3.x base score 6.4)
- EPSS exploit prediction: 0% (3rd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-209304
- Weakness: CWE-276
- Affected product: Redhat Openshift Update Service
- Published:
- Last modified:
Description
A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.
Frequently asked questions
- What is CVE-2025-57854?
- A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.
- How severe is CVE-2025-57854?
- CVE-2025-57854 has a CVSS 3.x base score of 6.4, rated medium severity. It is exploitable over local access with high attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-57854 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (3rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-57854?
- CVE-2025-57854 affects Redhat Openshift Update Service. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-57854?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-57854 have an EU (EUVD) identifier?
- Yes. CVE-2025-57854 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-209304.
- When was CVE-2025-57854 published?
- CVE-2025-57854 was published on 2026-04-08 and last updated on 2026-07-24.
References
- https://access.redhat.com/security/cve/CVE-2025-57854
- https://bugzilla.redhat.com/show_bug.cgi?id=2391107
Affected products (1)
- cpe:2.3:a:redhat:openshift_update_service:-:*:*:*:*:*:*:*
More vulnerabilities in Redhat Openshift Update Service
- CVE-2026-74243 — Medium (CVSS 6.5): A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote…
- CVE-2026-74245 — Medium (CVSS 5.9): A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could…
- CVE-2026-74244 — Medium (CVSS 5.9): A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated…
- CVE-2026-74240 — Medium (CVSS 5.4): A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on…
- CVE-2026-74242 — Medium (CVSS 5.3): A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's…
- CVE-2026-74241 — Medium (CVSS 4.8): A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When…
All CVEs affecting Redhat Openshift Update Service →
Other CWE-276 (Incorrect Default Permissions) vulnerabilities
- CVE-2022-42150 — Critical (CVSS 10.0): TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default…
- CVE-2020-29492 — Critical (CVSS 10.0): Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote…
- CVE-2020-29491 — Critical (CVSS 10.0): Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote…
- CVE-2025-40585 — Critical (CVSS 9.9): A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR…
- CVE-2019-19896 — Critical (CVSS 9.9): In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The…
- CVE-2020-37129 — Critical (CVSS 9.8): Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the…
Browse all CWE-276 (Incorrect Default Permissions) vulnerabilities →