Impact
gvproxy, the network forwarder provided by the gvisor‑tap‑vsock package, contains a path traversal flaw that allows an unauthenticated attacker to delete arbitrary files on the host. The /services/forwarder/expose endpoint does not validate the caller‑supplied socket path, enabling deletion of any file. This vulnerability can lead to loss of critical system files, interruption of services, and potentially provide a foothold for further exploitation. The weakness is a classic directory traversal flaw (CWE‑22).
Affected Systems
The affected products are all Red Hat‑branded environments that ship the gvisor‑tap‑vsock package, including the Red Hat Build of Podman Desktop, Red Hat Certification Program for RHEL 9, Red Hat Edge Manager 1, Red Hat Enterprise Linux 8, 9, 10, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces, and Red Hat OpenStack Platform 18.0. Version information is not specified, so any derivative using the vulnerable gvproxy component is potentially impacted.
Risk and Exploitability
The CVSS score of 9.3 places this flaw in the high‑severity range, and because the attacker does not need authentication the vulnerability is trivially exploitable over the network. Although the EPSS score is not available, the lack of authentication combined with the high damage potential means that exploitation is likely if an attacker can reach the exposed endpoint. Red Hat has not listed the flaw in the CISA KEV catalog, but the lack of a remedy in the advisory indicates urgent patching is required.
OpenCVE Enrichment