CVE-2025-5467

LOW

Apport 2.20.1-0ubuntu1-2.20.1-0ubuntu2.30 - Incorrect Group Ownership Assignment in Crash File Creation

Title source: llm
STIX 2.1

Description

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.

References (2)

Core 2

Scores

CVSS v3 3.3
EPSS 0.0002
EPSS Percentile 5.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-708
Status published
Products (1)
canonical/apport 2.20.1-0ubuntu1 - 2.20.1-0ubuntu2.30
Published Dec 10, 2025
Tracked Since Feb 18, 2026