THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-4437 (MEDIUM 5.7) — There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire /etc/passwd file into memory. If this file is excessively large, it c

[NVD] CVE-2025-4437 (MEDIUM 5.7) — There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire /etc/passwd file into memory. If this file is excessively large, it c

lownvdPublished 2025-08-20

CVE-2025-4437 CVSS: 5.7 MEDIUM Published: 2025-08-20T13:15:28.673

There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire /etc/passwd file into memory. If this file is excessively large, it can cause the a high memory consumption leading applic

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-4437