Bug 2372512 (CVE-2025-6020) - CVE-2025-6020 linux-pam: Linux-pam directory Traversal
Summary: CVE-2025-6020 linux-pam: Linux-pam directory Traversal
Keywords:
Status: NEW
Alias: CVE-2025-6020
Deadline: 2025-06-17
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-06-12 16:42 UTC by OSIDB Bzimport
Modified: 2025-10-01 02:43 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2025:10194 0 None None None 2025-07-02 08:06:27 UTC
Red Hat Product Errata RHBA-2025:10197 0 None None None 2025-07-02 08:03:41 UTC
Red Hat Product Errata RHBA-2025:10210 0 None None None 2025-07-02 10:33:28 UTC
Red Hat Product Errata RHBA-2025:10226 0 None None None 2025-07-02 13:45:30 UTC
Red Hat Product Errata RHBA-2025:10227 0 None None None 2025-07-02 14:09:17 UTC
Red Hat Product Errata RHBA-2025:10228 0 None None None 2025-07-02 14:18:19 UTC
Red Hat Product Errata RHBA-2025:10234 0 None None None 2025-07-02 14:23:57 UTC
Red Hat Product Errata RHBA-2025:10420 0 None None None 2025-07-07 13:04:13 UTC
Red Hat Product Errata RHBA-2025:10650 0 None None None 2025-07-08 15:38:33 UTC
Red Hat Product Errata RHBA-2025:11147 0 None None None 2025-07-15 13:09:53 UTC
Red Hat Product Errata RHBA-2025:11345 0 None None None 2025-07-16 18:21:42 UTC
Red Hat Product Errata RHBA-2025:11447 0 None None None 2025-07-21 11:13:12 UTC
Red Hat Product Errata RHBA-2025:14582 0 None None None 2025-08-26 08:28:44 UTC
Red Hat Product Errata RHBA-2025:14642 0 None None None 2025-08-26 15:35:07 UTC
Red Hat Product Errata RHBA-2025:14829 0 None None None 2025-08-28 06:51:13 UTC
Red Hat Product Errata RHBA-2025:15459 0 None None None 2025-09-08 13:36:10 UTC
Red Hat Product Errata RHBA-2025:15610 0 None None None 2025-09-10 11:20:22 UTC
Red Hat Product Errata RHBA-2025:16948 0 None None None 2025-09-29 12:46:37 UTC
Red Hat Product Errata RHBA-2025:9772 0 None None None 2025-06-26 11:37:13 UTC
Red Hat Product Errata RHSA-2025:10024 0 None None None 2025-07-01 08:17:44 UTC
Red Hat Product Errata RHSA-2025:10027 0 None None None 2025-07-01 08:44:14 UTC
Red Hat Product Errata RHSA-2025:10180 0 None None None 2025-07-02 05:21:36 UTC
Red Hat Product Errata RHSA-2025:10354 0 None None None 2025-07-07 02:33:18 UTC
Red Hat Product Errata RHSA-2025:10357 0 None None None 2025-07-07 02:23:46 UTC
Red Hat Product Errata RHSA-2025:10358 0 None None None 2025-07-07 02:32:37 UTC
Red Hat Product Errata RHSA-2025:10359 0 None None None 2025-07-07 02:23:23 UTC
Red Hat Product Errata RHSA-2025:10361 0 None None None 2025-07-07 02:00:47 UTC
Red Hat Product Errata RHSA-2025:10362 0 None None None 2025-07-07 02:11:45 UTC
Red Hat Product Errata RHSA-2025:11386 0 None None None 2025-07-17 15:27:11 UTC
Red Hat Product Errata RHSA-2025:14557 0 None None None 2025-08-26 01:27:26 UTC
Red Hat Product Errata RHSA-2025:15099 0 None None None 2025-09-03 00:50:18 UTC
Red Hat Product Errata RHSA-2025:15358 0 None None None 2025-09-04 16:30:05 UTC
Red Hat Product Errata RHSA-2025:15827 0 None None None 2025-09-15 15:13:29 UTC
Red Hat Product Errata RHSA-2025:15828 0 None None None 2025-09-15 15:14:17 UTC
Red Hat Product Errata RHSA-2025:9526 0 None None None 2025-06-24 12:14:17 UTC

Description OSIDB Bzimport 2025-06-12 16:42:52 UTC
The module pam_namespace in linux-pam <= 1.7.0 may access user-controlled paths without proper protections, which allows a local user to elevate their privileges to root via multiple symlink attacks and race conditions.

Comment 2 errata-xmlrpc 2025-06-24 12:14:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:9526 https://access.redhat.com/errata/RHSA-2025:9526

Comment 3 errata-xmlrpc 2025-07-01 08:17:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:10024 https://access.redhat.com/errata/RHSA-2025:10024

Comment 4 errata-xmlrpc 2025-07-01 08:44:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:10027 https://access.redhat.com/errata/RHSA-2025:10027

Comment 5 errata-xmlrpc 2025-07-02 05:21:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:10180 https://access.redhat.com/errata/RHSA-2025:10180

Comment 10 errata-xmlrpc 2025-07-07 02:00:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support

Via RHSA-2025:10361 https://access.redhat.com/errata/RHSA-2025:10361

Comment 11 errata-xmlrpc 2025-07-07 02:11:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:10362 https://access.redhat.com/errata/RHSA-2025:10362

Comment 12 errata-xmlrpc 2025-07-07 02:23:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:10359 https://access.redhat.com/errata/RHSA-2025:10359

Comment 13 errata-xmlrpc 2025-07-07 02:23:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:10357 https://access.redhat.com/errata/RHSA-2025:10357

Comment 14 errata-xmlrpc 2025-07-07 02:32:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:10358 https://access.redhat.com/errata/RHSA-2025:10358

Comment 15 errata-xmlrpc 2025-07-07 02:33:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:10354 https://access.redhat.com/errata/RHSA-2025:10354

Comment 27 errata-xmlrpc 2025-07-17 15:27:09 UTC
This issue has been addressed in the following products:

  RHEL-8 based Middleware Containers

Via RHSA-2025:11386 https://access.redhat.com/errata/RHSA-2025:11386

Comment 40 errata-xmlrpc 2025-08-26 01:27:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:14557 https://access.redhat.com/errata/RHSA-2025:14557

Comment 45 errata-xmlrpc 2025-09-03 00:50:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:15099 https://access.redhat.com/errata/RHSA-2025:15099

Comment 46 errata-xmlrpc 2025-09-04 16:30:04 UTC
This issue has been addressed in the following products:

  RHEL-8 based Middleware Containers

Via RHSA-2025:15358 https://access.redhat.com/errata/RHSA-2025:15358

Comment 48 errata-xmlrpc 2025-09-15 15:13:27 UTC
This issue has been addressed in the following products:

  Red Hat Web Terminal 1.12 on RHEL 9

Via RHSA-2025:15827 https://access.redhat.com/errata/RHSA-2025:15827

Comment 49 errata-xmlrpc 2025-09-15 15:14:15 UTC
This issue has been addressed in the following products:

  Red Hat Web Terminal 1.11 on RHEL 9

Via RHSA-2025:15828 https://access.redhat.com/errata/RHSA-2025:15828


Note You need to log in before you can comment on or make changes to this bug.