Description
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
0:1.1.8-23.el7_9.2 before *
0:1.3.1-38.el8_10 before *
0:1.3.1-8.el8_2.2 before *
0:1.3.1-14.el8_4.2 before *
0:1.3.1-14.el8_4.2 before *
0:1.3.1-16.el8_6.3 before *
0:1.3.1-16.el8_6.3 before *
0:1.3.1-16.el8_6.3 before *
0:1.3.1-26.el8_8.2 before *
0:1.3.1-26.el8_8.2 before *
0:1.5.1-26.el9_6 before *
0:1.5.1-26.el9_6 before *
0:1.5.1-9.el9_0.3 before *
0:1.5.1-15.el9_2.2 before *
0:1.5.1-24.el9_4.1 before *
1.11-19 before *
1.11-8 before *
1.12-4 before *
sha256:c85cfbcaf7888885e57596b7b8bde3894718cfc33326499b24961a66a62cf083 before *
sha256:24722900db1425bf0c27f6ad6f3fb7d79ff9ebc433bdab58423fa71bab76122b before *
sha256:9ff002e628e5646b5ab3cc9201087847bea29569b4a1bc135b89d5c1a5f0a422 before *
sha256:8f29671308ca658e32e97d5c3b482f7541aae1bca1b71f39b3276a9a334d8108 before *
sha256:8caeae7ffadf08840a47bc90c390ff402dd7db11457bca48f4e08a11e394be74 before *
Timeline
2025-08-13: | Reported to Red Hat. |
2025-08-13: | Made public. |
References
access.redhat.com/errata/RHSA-2025:14557 (RHSA-2025:14557)
access.redhat.com/errata/RHSA-2025:15099 (RHSA-2025:15099)
access.redhat.com/errata/RHSA-2025:15100 (RHSA-2025:15100)
access.redhat.com/errata/RHSA-2025:15101 (RHSA-2025:15101)
access.redhat.com/errata/RHSA-2025:15102 (RHSA-2025:15102)
access.redhat.com/errata/RHSA-2025:15103 (RHSA-2025:15103)
access.redhat.com/errata/RHSA-2025:15104 (RHSA-2025:15104)
access.redhat.com/errata/RHSA-2025:15105 (RHSA-2025:15105)
access.redhat.com/errata/RHSA-2025:15106 (RHSA-2025:15106)
access.redhat.com/errata/RHSA-2025:15107 (RHSA-2025:15107)
access.redhat.com/errata/RHSA-2025:15709 (RHSA-2025:15709)
access.redhat.com/errata/RHSA-2025:15827 (RHSA-2025:15827)
access.redhat.com/errata/RHSA-2025:15828 (RHSA-2025:15828)
access.redhat.com/errata/RHSA-2025:16524 (RHSA-2025:16524)
access.redhat.com/security/cve/CVE-2025-8941
bugzilla.redhat.com/show_bug.cgi?id=2388220 (RHBZ#2388220)