VDB

CVE-2025-57852

CVE-2025-57852 PUBLISHED CVSS 6.400000095367432 MEDIUM

A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.

EPSS 0.01% · 1.9th percentile

Risk Scores

CVSS v3.1
6.400000095367432
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.01%
1.9th percentile

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift AI 2.16sha256:97e2bd9b587f08e135a9aeb9b3e0dc6eafa1a9bdacbb5ecb681ce9bd5aa37fc9
Red HatRed Hat OpenShift AI 2.22sha256:1709fa3c79aad4ba7eb9be8299949396092c8e20210124e0c0936385bc04e839
Red HatRed Hat OpenShift AI 2.21*
Red HatRed Hat OpenShift AI 2.19sha256:53ac36baa374159b9065c718a9ede821bbb61d9ebe9502b2243e0a9f7aca0d16
Red HatRed Hat OpenShift AI 2.24*

Timeline

  • Sep 30, 2025 CVE Published
  • Oct 1, 2025 EPSS Score
  • Oct 8, 2025 EPSS Score
  • Oct 14, 2025 EPSS Score
  • Oct 21, 2025 EPSS Score
  • Oct 27, 2025 EPSS Score
  • Nov 3, 2025 EPSS Score
  • Nov 9, 2025 EPSS Score
  • Nov 16, 2025 EPSS Score
  • Nov 22, 2025 EPSS Score
  • Nov 29, 2025 EPSS Score
  • Dec 6, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›