Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.
{
"cna_assigner": "Google",
"cwe_ids": [
"CWE-266"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/2xxx/CVE-2025-2713.json"
}{
"cpe": "cpe:2.3:a:google:gvisor:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "20240325.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-2713.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"987311230596704344963499087642512643",
"71951412179097876717608766614907006387",
"160707445793111294189659153068046278640",
"144516135713139208523067105826992476969",
"98274917187627560292695531658977843199",
"280038435893020112415055307429409833632",
"65570565448779031504661038384452736637",
"162175069984543986683411973822755644117",
"224182529936298398885381809273423839089",
"106461853330453344771300417014098745254",
"60202344809128481004252555690415696349",
"60063360857373039625478709454960523353",
"232824914436416352972637396424806301571",
"192492773791665838436033261265162205908",
"17547826281782737523060171366706858914"
],
"threshold": 0.9
},
"id": "CVE-2025-2713-03e5ed0f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/google/gvisor/commit/e1ffb147787ac37d003c60519a7e859a80f89b1f",
"target": {
"file": "test/util/test_util.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "216268905067353538568695623042931707340",
"length": 99
},
"id": "CVE-2025-2713-79a8757a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/google/gvisor/commit/e1ffb147787ac37d003c60519a7e859a80f89b1f",
"target": {
"file": "test/util/test_util.h",
"function": "SpecificErrno"
}
}
]
"2026-08-12T15:16:20Z"