CVE-2025-38499

MEDIUM

Linux kernel - Privilege Escalation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns What we want is to verify there is that clone won't expose something hidden by a mount we wouldn't be able to undo. "Wouldn't be able to undo" may be a result of MNT_LOCKED on a child, but it may also come from lacking admin rights in the userns of the namespace mount belongs to. clone_private_mnt() checks the former, but not the latter. There's a number of rather confusing CAP_SYS_ADMIN checks in various userns during the mount, especially with the new mount API; they serve different purposes and in case of clone_private_mnt() they usually, but not always end up covering the missing check mentioned above.

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 7.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (31)
debian/debian_linux 11.0
Linux/Linux < 5.14
Linux/Linux 4.14.244 - 4.15
Linux/Linux 4.19.204 - 4.20
Linux/Linux 4.4.281 - 4.5
Linux/Linux 4.9.280 - 4.10
Linux/Linux 41812f4b84484530057513478c6770590347dc30
Linux/Linux 427215d85e8d1476da1a86b8d67aceb485eb3631 - 36fecd740de2d542d2091d65d36554ee2bcf9c65
Linux/Linux 427215d85e8d1476da1a86b8d67aceb485eb3631 - 38628ae06e2a37770cd794802a3f1310cf9846e3
Linux/Linux 427215d85e8d1476da1a86b8d67aceb485eb3631 - c28f922c9dcee0e4876a2c095939d77fe7e15116
... and 21 more
Published Aug 11, 2025
Tracked Since Feb 18, 2026