← Back

CVE-2025-4598

nvd nist
Published: May 30, 2025Modified: Jun 30, 2026

JSON object

Loading...
4.7
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.0 / Impact: 3.6
Source: secalert@redhat.com (Secondary)

Description

A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.

Affected (16)

Show all products
Systemd
2 products
Enterprise Linux
Openshift Container Platform
1 product
Debian Linux
1 product
Linux
1 product
Linux Kernel
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Systemd Project
Before 252.37
From 253 to 253.32
From 254 to 254.25
From 255 to 255.19
From 256 to 256.14
From 257 to 257.6
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 10.0
Version 7.0
Version 8.0
Version 9.0
Version 4.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 11.0
Version 12.0
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 8
Version 9
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.16

References (19)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue Tracking
Source: secalert@redhat.com
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e

Timeline

No history available yet.