Куда я попал?
CVE-2025-8941
PUBLISHED
16.10.2025
CNA: redhat
Linux-pam: incomplete fix for cve-2025-6020
Обновлено:
16.10.2025
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
CWE
| Идентификатор | Описание |
|---|---|
| CWE-22 | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
НКЦКИ уязвимости
Бюллетени НКЦКИ - уязвимости ПО
| Идентификатор | Дата бюллетеня | Описание |
|---|---|---|
| VULN:20251009-17 | 09.10.2025 | Повышение привилегий в Multicluster Engine for Kubernetes 2.8 |
CVSS
| Оценка | Severity | Версия | Базовый вектор |
|---|---|---|---|
| 7.8 | HIGH | 3.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Доп. Информация
Product Status
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 Extended Lifecycle Support | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.2 Advanced Update Support | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.2 Advanced Update Support | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.6 Telecommunications Update Service | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 9 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 9 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Enterprise Linux 9.4 Extended Update Support | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9.4 Extended Update Support | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Web Terminal 1.11 on RHEL 9 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Web Terminal 1.11 on RHEL 9 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Web Terminal 1.11 on RHEL 9 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Web Terminal 1.11 on RHEL 9 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Web Terminal 1.12 on RHEL 9 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Web Terminal 1.12 on RHEL 9 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| cert-manager operator for Red Hat OpenShift 1.16 | |||||
|---|---|---|---|---|---|
| Product: | cert-manager operator for Red Hat OpenShift 1.16 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat Discovery 2 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat Discovery 2 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift sandboxed containers 1.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift sandboxed containers 1.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift sandboxed containers 1.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift sandboxed containers 1.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift sandboxed containers 1.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift sandboxed containers 1.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
| Red Hat OpenShift sandboxed containers 1.1 | |||||
|---|---|---|---|---|---|
| Product: | Red Hat OpenShift sandboxed containers 1.1 | ||||
| Vendor: | Red Hat | ||||
| Default status: | affected | ||||
| Версии: |
|
||||
| СPE: |
|
||||
Ссылки
CISA ADP Vulnrichment
Обновлено:
14.08.2025
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.
SSVC
| Exploitation | Automatable | Technical Impact | Версия | Дата доступа |
|---|---|---|---|---|
| none | no | total | 2.0.3 | 13.08.2025 |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.