Executive brief
A security flaw was identified in the Red Hat OpenShift Update Service, a tool used to manage updates for OpenShift clusters. Due to incorrect file permissions, an attacker who already has limited access to a container could gain full administrative control (root privileges) over that specific container. This could allow them to bypass security restrictions or access sensitive data within the containerized environment.
Technical details
A privilege escalation vulnerability (CWE-276) exists in Red Hat OpenShift Update Service (OSUS) container images where the /etc/passwd file is created with group-writable permissions at build time. An attacker who can execute commands within the container—even as a non-root user—can leverage membership in the 'root' group to modify /etc/passwd. By adding a new user entry with UID 0, the attacker can achieve full root privileges within the container environment. This exploit requires local access and is categorized with high complexity as it depends on specific container configurations and group memberships.
Affected products
- Red Hat OpenShift Update Service (OSUS) Operator 5
Timeline
- 2025-08-26: other: Initial report in Red Hat Bugzilla
- 2026-04-08: disclosed: Public disclosure of CVE-2025-57854