Куда я попал?
CVE-2025-6020
PUBLISHED
21.10.2025
CNA: redhat
Linux-pam: linux-pam directory traversal
Обновлено:
16.10.2025
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
CWE
| Идентификатор | Описание |
|---|---|
| CWE-22 | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
БДУ ФСТЭК
| Идентификатор | Описание |
|---|---|
| BDU:2025-07273 | Уязвимость модуля pam_namespace модуля аутентификации Linux-PAM, позволяющая нарушителю повысить свои привилегии |
НКЦКИ уязвимости
Бюллетени НКЦКИ - уязвимости ПО
| Идентификатор | Дата бюллетеня | Описание |
|---|---|---|
| VULN:20251009-20 | 09.10.2025 | Выполнение произвольного кода в Multicluster Engine for Kubernetes 2.8 |
CVSS
| Оценка | Severity | Версия | Базовый вектор |
|---|---|---|---|
| 7.8 | HIGH | 3.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Доп. Информация
Product Status
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 Extended Lifecycle Support | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.2 Advanced Update Support | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.2 Advanced Update Support | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.6 Telecommunications Update Service | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 9 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 9 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 9 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 9 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 9.4 Extended Update Support | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9.4 Extended Update Support | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Web Terminal 1.11 on RHEL 9 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Web Terminal 1.11 on RHEL 9 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Web Terminal 1.11 on RHEL 9 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Web Terminal 1.11 on RHEL 9 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Web Terminal 1.12 on RHEL 9 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Web Terminal 1.12 on RHEL 9 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| RHEL-8 based Middleware Containers | |||||
|---|---|---|---|---|---|
| Product: | RHEL-8 based Middleware Containers | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| RHEL-8 based Middleware Containers | |||||
|---|---|---|---|---|---|
| Product: | RHEL-8 based Middleware Containers | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| RHEL-8 based Middleware Containers | |||||
|---|---|---|---|---|---|
| Product: | RHEL-8 based Middleware Containers | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| RHEL-8 based Middleware Containers | |||||
|---|---|---|---|---|---|
| Product: | RHEL-8 based Middleware Containers | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| RHEL-8 based Middleware Containers | |||||
|---|---|---|---|---|---|
| Product: | RHEL-8 based Middleware Containers | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| RHEL-8 based Middleware Containers | |||||
|---|---|---|---|---|---|
| Product: | RHEL-8 based Middleware Containers | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| RHEL-8 based Middleware Containers | |||||
|---|---|---|---|---|---|
| Product: | RHEL-8 based Middleware Containers | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| RHEL-8 based Middleware Containers | |||||
|---|---|---|---|---|---|
| Product: | RHEL-8 based Middleware Containers | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| RHEL-8 based Middleware Containers | |||||
|---|---|---|---|---|---|
| Product: | RHEL-8 based Middleware Containers | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| cert-manager operator for Red Hat OpenShift 1.16 | |||||
|---|---|---|---|---|---|
| Product: | cert-manager operator for Red Hat OpenShift 1.16 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Discovery 2 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Discovery 2 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Discovery 2 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Discovery 2 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift distributed tracing 3.6.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift distributed tracing 3.6.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift distributed tracing 3.6.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift distributed tracing 3.6.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift distributed tracing 3.6.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift distributed tracing 3.6.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift distributed tracing 3.6.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift distributed tracing 3.6.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift distributed tracing 3.6.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift distributed tracing 3.6.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift distributed tracing 3.6.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift distributed tracing 3.6.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift distributed tracing 3.6.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift distributed tracing 3.6.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift distributed tracing 3.6.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift distributed tracing 3.6.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift distributed tracing 3.6.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift distributed tracing 3.6.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift sandboxed containers 1.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift sandboxed containers 1.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift sandboxed containers 1.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift sandboxed containers 1.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift sandboxed containers 1.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift sandboxed containers 1.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift sandboxed containers 1.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift sandboxed containers 1.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 10 | |
|---|---|
| Product: | Red Hat Enterprise Linux 10 |
| Vendor: | Red Hat |
| Default status: | affected |
| СPE: |
|
Ссылки
CISA ADP Vulnrichment
Обновлено:
21.10.2025
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.
SSVC
| Exploitation | Automatable | Technical Impact | Версия | Дата доступа |
|---|---|---|---|---|
| none | no | total | 2.0.3 | 17.06.2025 |
CVE Program Container
Обновлено:
17.06.2025
SSVC and KEV, plus CVSS and CWE if not provided by the CNA.
Ссылки
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.