CVE-2025-5467

LOW

Canonical Apport - Info Disclosure

Title source: llm

Description

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.

Scores

CVSS v3 3.3
EPSS 0.0002
EPSS Percentile 4.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-708
Status published

Affected Products (1)

canonical/apport < 2.20.1-0ubuntu2.30

Timeline

Published Dec 10, 2025
Tracked Since Feb 18, 2026