The UnMountPodLogs and LinkContainerLogs functions in CRI-O do not properly validate the emptyDirVolName parameter, making them vulnerable to a path traversal attack. An attacker can exploit this to unmount arbitrary paths on the host system, potentially causing denial of service or compromising system integrity.
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:1122 https://access.redhat.com/errata/RHSA-2025:1122