logo

Qualys TRU Discovers Two Local Information Disclosure Vulnerabilities in Apport and systemd-coredump: CVE-2025-5054 and CVE-2025-4598

ID: 24f7482e-6e79-5b88-b5c0-dc59f66d7109

STIX ID: report--24f7482e-6e79-5b88-b5c0-dc59f66d7109

Feed Name: Qualys Blog

Threat Score
70/100

Date Published: 2025-05-29

Date Updated: 2026-04-28

Author: Saeed Abbasi

...
...

Qualys TRU disclosed two race-condition information-disclosure vulnerabilities (CVE-2025-5054 in Apport and CVE-2025-4598 in systemd-coredump) that allow local attackers to extract sensitive data from core dumps of SUID programs; PoCs show theft of /etc/shadow password hashes via unix_chkpwd crashes. Affected systems include Ubuntu (Apport) and Fedora/RHEL 9/10 (systemd-coredump); mitigations include disabling SUID core dumps (/proc/sys/fs/suid_dumpable=0), applying patches, and using Qualys TruRisk Eliminate for rapid mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.