CVE-2025-4598

MEDIUM

systemd-coredump - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.

References (19)

Core 19
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:22660
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:22868
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:23227
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:23234
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2026:0414
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2026:1652
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:18153
https://access.redhat.com/errata/RHSA-2026:18153
Vendor Advisory vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2025-4598
Issue Tracking issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2369242

Scores

CVSS v3 4.7
EPSS 0.0011
EPSS Percentile 28.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-364
Status published
Products (30)
debian/debian_linux 11.0
debian/debian_linux 12.0
linux/linux_kernel < 6.16
oracle/linux 8
oracle/linux 9
Red Hat/Red Hat Ceph Storage 7 7
Red Hat/Red Hat Ceph Storage 7 sha256:cfaf2a3c9513bd280265b0e2ca5f7d60022a2e362027becfeb2c133179925523
Red Hat/Red Hat Ceph Storage 8 1769512383
Red Hat/Red Hat Ceph Storage 8 8
Red Hat/Red Hat Ceph Storage 8 sha256:97a60239048123bc963d7c9ac2ad85caa6a254759e44c15f173ca12ea51e4719
... and 20 more
Published May 30, 2025
Tracked Since Feb 18, 2026