PT-2025-25653 · Linux Pam+9 · Linux-Pam+9

·

CVE-2025-6020

·

Published

2025-01-01

·

Updated

2026-08-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions linux-pam (affected versions not specified)
Description A flaw in the pam namespace module of linux-pam allows local users to elevate their privileges to root via multiple symlink attacks and race conditions. This occurs when a user can launch a process outside of the mount namespace created by pam namespace, enabling them to exploit the issue. The estimated number of potentially affected devices worldwide is not available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

LPE

Race Condition

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:10027
ALSA-2025:14557
ALSA-2025:15099
ALSA-2025:20181
ALSA-2025:9526
AZL-64113
AZL-64142
BDU:2025-07273
CESA-2025_10027
CESA-2025_14557
CVE-2025-6020
DLA-4306-1
ECHO-5CF6-3556-3B34
GHSA-F9P8-GJR4-J9GX
INFSA-2025_10027
INFSA-2025_14557
INFSA-2025_15099
INFSA-2025_9526
OESA-2025-1743
OESA-2025-1744
OESA-2025-1745
OESA-2025-1746
OESA-2025-1830
OESA-2025-1831
OPENSUSE-SU-2025:15256-1
RHSA-2025:10024
RHSA-2025:10027
RHSA-2025:10180
RHSA-2025:10354
RHSA-2025:10357
RHSA-2025:10358
RHSA-2025:10359
RHSA-2025:10361
RHSA-2025:10362
RHSA-2025:14557
RHSA-2025:15099
RHSA-2025:20181
RHSA-2025:22019
RHSA-2025:9526
RHSA-2025_10027
RHSA-2025_14557
RHSA-2025_15099
RHSA-2025_9526
SUSE-SU-2025:02013-1
SUSE-SU-2025:20427-1
SUSE-SU-2025:20441-1
SUSE-SU-2025_02013-1
USN-7580-1

Affected Products

Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Linux-Pam