A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Aug 2025 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 13 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 13 Aug 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020. | |
Title | Linux-pam: incomplete fix for cve-2025-6020 | |
First Time appeared |
Redhat
Redhat enterprise Linux |
|
Weaknesses | CWE-22 | |
CPEs | cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
Vendors & Products |
Redhat
Redhat enterprise Linux |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-08-14T03:56:00.871Z
Reserved: 2025-08-13T12:24:47.522Z
Link: CVE-2025-8941

Updated: 2025-08-13T14:50:43.534Z

Status : Awaiting Analysis
Published: 2025-08-13T15:15:41.873
Modified: 2025-08-13T17:33:46.673
Link: CVE-2025-8941
