New Linux Vulnerabilities
ID: 402a1a3b-aeb6-52e4-b5cc-efad70377880
STIX ID: report--402a1a3b-aeb6-52e4-b5cc-efad70377880
Feed Name: Schneier on Security
Threat Score
The post reports two moderate-severity Linux race-condition flaws (CVE-2025-5054 and CVE-2025-4598) in crash-handling tools (apport and systemd-coredump) whereby a local attacker who induces a privileged process crash and quickly replaces it within a mount/pid namespace can cause sensitive data from core dumps (potentially including password hashes) to be forwarded into the namespace; distributions like Ubuntu, RHEL, and Fedora are noted and remediation is advised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
