web analytics

New Linux Vulnerabilities – Source: www.schneier.com

Rate this post

Source: www.schneier.com – Author: Bruce Schneier

They’re interesting:

Tracked as CVE-2025-5054 and CVE-2025-4598, both vulnerabilities are race condition bugs that could enable a local attacker to obtain access to access sensitive information. Tools like Apport and systemd-coredump are designed to handle crash reporting and core dumps in Linux systems.

[…]

“This means that if a local attacker manages to induce a crash in a privileged process and quickly replaces it with another one with the same process ID that resides inside a mount and pid namespace, apport will attempt to forward the core dump (which might contain sensitive information belonging to the original, privileged process) into the namespace.”

Moderate severity, but definitely worth fixing.

Slashdot thread.

Tags: , ,

Posted on June 3, 2025 at 7:07 AM0 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Original Post URL: https://www.schneier.com/blog/archives/2025/06/new-linux-vulnerabilities.html

Category & Tags: Uncategorized,Linux,passwords,vulnerabilities – Uncategorized,Linux,passwords,vulnerabilities

Views: 4

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post