logo

New Linux Vulnerabilities

ID: 402a1a3b-aeb6-52e4-b5cc-efad70377880

STIX ID: report--402a1a3b-aeb6-52e4-b5cc-efad70377880

Feed Name: Schneier on Security

Threat Score
50/100

Date Published: 2025-06-03

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

The post reports two moderate-severity Linux race-condition flaws (CVE-2025-5054 and CVE-2025-4598) in crash-handling tools (apport and systemd-coredump) whereby a local attacker who induces a privileged process crash and quickly replaces it within a mount/pid namespace can cause sensitive data from core dumps (potentially including password hashes) to be forwarded into the namespace; distributions like Ubuntu, RHEL, and Fedora are noted and remediation is advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.