PT-2026-25885 · Linux+2 · Linux Kernel+2

CVE-2025-71239

·

Publicado

2025-01-01

·

Atualizado

2026-08-30

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 6.6 and later
Description The Linux kernel includes an issue where the fchmodat2() function, introduced in version 6.6, was not included in the audit change attributes class. Calling fchmodat2() to modify file attributes in a manner similar to chmod() or fchmodat() could bypass audit rules, such as those defined with the -w flag. The current patch resolves this by adding fchmodat2() to the change attributes class. The fchmodat2() function allows changing file attributes. The audit rules are used to track file access and modifications. Bypassing these rules could allow unauthorized changes to file permissions and ownership.
Recommendations Linux kernel version 6.6 and later: Update the kernel to include the patch that adds fchmodat2() to the change attributes class.

Exploit

Correção

Protection Mechanism Failure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-79914
BDU:2026-11823
CVE-2025-71239
OESA-2026-2581
OPENSUSE-SU-2026:20572-1
SUSE-SU-2026:21230-1
SUSE-SU-2026:21237-1
SUSE-SU-2026:21352-1
SUSE-SU-2026:21361-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8597-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8668-1

Produtos afetados

Linuxmint
Linux Kernel
Ubuntu