Logo
vulnerabilityCVE-2025-6020
Name
CVE-2025-6020
Source
NVD ( link)Debian ( link)
Description
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
linux-pam
Patched

Vulnerability Ratings#


7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
1.7.2
Not Affected
openwrt
master
1.7.1-r5
Not Affected
openwrt
openwrt-25.12
1.7.1-r5
Not Affected

Resolved with patches#


linux-pam (buildroot:2025.02.x)

#
Title
Author
Resolve
1
pam_namespace: fix potential privilege escalation
Olivier Bal-Petre <olivier.bal-petre@ssi.gouv.fr>
CVE-2025-6020
2
pam_namespace: secure_opendir: do not look at the group
"Dmitry V. Levin" <ldv@strace.io>
CVE-2025-6020
3
pam_namespace: add flags to indicate path safety
Olivier Bal-Petre <olivier.bal-petre@ssi.gouv.fr>
CVE-2025-6020