VulnerabilityDeferred
CVE-2025-31160
atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or possibly have unspecified other impact by running certain types of unprivileged processes while a different user runs atop.
LOW 2.9EPSS 0.20%
Does this matter?
Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.
Description
atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or possibly have unspecified other impact by running certain types of unprivileged processes while a different user runs atop.
- CVSS 3.1
- 2.9 LOWCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 0.20% probability · 10th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-617
- Source
- cve@mitre.org
References
- https://blog.bismuth.sh/blog/bismuth-found-the-atop-bug
- https://github.com/Atoptool/atop
- https://news.ycombinator.com/item?id=43477057
- https://news.ycombinator.com/item?id=43485980
- https://rachelbythebay.com/w/2025/03/26/atop/
- http://www.openwall.com/lists/oss-security/2025/03/26/3
- http://www.openwall.com/lists/oss-security/2025/03/27/1
- http://www.openwall.com/lists/oss-security/2025/03/27/2
- http://www.openwall.com/lists/oss-security/2025/03/27/3
- http://www.openwall.com/lists/oss-security/2025/03/29/1
- https://lists.debian.org/debian-lts-announce/2025/04/msg00013.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.