Linux-pam: linux-pam directory traversal
Summary
| CVE | CVE-2025-6020 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-06-17 13:15:21 UTC |
| Updated | 2026-05-12 13:17:27 UTC |
| Description | A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.000720000 probability, percentile 0.218310000 (date 2026-05-12)
Problem Types: CWE-22 | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Enterprise Linux 10 | unaffected 0:1.6.1-8.el10 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | unaffected 0:1.6.1-8.el10_0 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | unaffected 0:1.1.8-23.el7_9.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 0:1.3.1-37.el8_10 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 0:1.3.1-38.el8_10 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | unaffected 0:1.3.1-8.el8_2.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | unaffected 0:1.3.1-14.el8_4.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | unaffected 0:1.3.1-16.el8_6.2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Telecommunications Update Service | unaffected 0:1.3.1-16.el8_6.2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions | unaffected 0:1.3.1-16.el8_6.2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | unaffected 0:1.3.1-26.el8_8.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions | unaffected 0:1.3.1-26.el8_8.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:1.5.1-26.el9_6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:1.5.1-25.el9_6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:1.5.1-26.el9_6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:1.5.1-25.el9_6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions | unaffected 0:1.5.1-9.el9_0.2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions | unaffected 0:1.5.1-15.el9_2.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | unaffected 0:1.5.1-24.el9_4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Web Terminal 1.11 On RHEL 9 | unaffected 1.11-19 * rpm | Not specified |
| CNA | Red Hat | Red Hat Web Terminal 1.11 On RHEL 9 | unaffected 1.11-8 * rpm | Not specified |
| CNA | Red Hat | Red Hat Web Terminal 1.12 On RHEL 9 | unaffected 1.12-4 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.5-4.1752066672 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.5-4.1752065732 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.5-4.1752065732 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.5-3.1752065737 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.5-4.1752065731 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.5-25 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.5-4.1752065736 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.5-2.1752065733 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.13.5-4.1752065755 * rpm | Not specified |
| CNA | Red Hat | RHOSS-1.36-RHEL-8 | unaffected 1.36.0-11 * rpm | Not specified |
| CNA | Red Hat | RHOSS-1.36-RHEL-8 | unaffected 1.36.0-11 * rpm | Not specified |
| CNA | Red Hat | RHOSS-1.36-RHEL-8 | unaffected 1.36.0-11 * rpm | Not specified |
| CNA | Red Hat | RHOSS-1.36-RHEL-8 | unaffected 1.36.0-10 * rpm | Not specified |
| CNA | Red Hat | RHOSS-1.36-RHEL-8 | unaffected 1.36.0-10 * rpm | Not specified |
| CNA | Red Hat | RHOSS-1.36-RHEL-8 | unaffected 1.36.0-4 * rpm | Not specified |
| CNA | Red Hat | RHOSS-1.36-RHEL-8 | unaffected 1.36.0-9 * rpm | Not specified |
| CNA | Red Hat | RHOSS-1.36-RHEL-8 | unaffected 1.36.0-18 * rpm | Not specified |
| CNA | Red Hat | RHOSS-1.36-RHEL-8 | unaffected 1.36.0-11 * rpm | Not specified |
| CNA | Red Hat | RHOSS-1.36-RHEL-8 | unaffected 1.36.0-7 * rpm | Not specified |
| CNA | Red Hat | Cert-manager Operator For Red Hat OpenShift 1.16 | unaffected sha256:1abdfac084e7c86e7a93a19e5cf6b54db79b903bfb7474a42200f753b29eda4b * rpm | Not specified |
| CNA | Red Hat | OpenShift Compliance Operator 1 | unaffected sha256:06ad8599c4b0170264e40a45b0126504c87c37f0832265c7ff6541d2385b2049 * rpm | Not specified |
| CNA | Red Hat | Red Hat Discovery 2 | unaffected sha256:bd9cb502def3153c193713b56372694cb555a71b38d4fc0fd9d021bccc5602de * rpm | Not specified |
| CNA | Red Hat | Red Hat Discovery 2 | unaffected sha256:1c67d8d526ab4f2854947f7dccd8752a2efd414c0f1cbab17706fa91147e7cda * rpm | Not specified |
| CNA | Red Hat | Red Hat Insights Proxy 1.5 | unaffected sha256:4ca38b33efec0d2dd17a8fd822a7c18281810676ceabb0c1db90953cb91cd5ea * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Distributed Tracing 3.6.0 | unaffected sha256:1faa5daf085b0844740653d96711b3fcfa766a77224fb523335d877b8e314b57 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Distributed Tracing 3.6.0 | unaffected sha256:39378c1e705973edca5f52f422b5c3693aaf5d2f22fb320d7676086b2cf846ba * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Distributed Tracing 3.6.0 | unaffected sha256:18ca3c44f6f25cbfe67842a0b2c9491a8247a64dbd166f188dccf0a84cfd3e67 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Distributed Tracing 3.6.0 | unaffected sha256:34851d4dd94a887b27d0937a1238d09ac370b4ec06382fe880796dac86c4aa3e * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Distributed Tracing 3.6.0 | unaffected sha256:3d281c9d7fe151c35605aac57a95fec699d20ecea6f4a5ea5b8cdc26a8808695 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Distributed Tracing 3.6.0 | unaffected sha256:2a37885dbd9735167854119a546f9ce1b37454a2b57d283fbd8da890c01db767 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Distributed Tracing 3.6.0 | unaffected sha256:8f2da1e0fc45a36cffbe91f9a1c4449eb0c71671865b7194951ad727c9f7b064 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Distributed Tracing 3.6.0 | unaffected sha256:1feaee0df48953c919df3ceb2dde3aa10345e69c0b1a7186a8a0fd6ab9b300f6 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Distributed Tracing 3.6.0 | unaffected sha256:54c5403a8a9e0300233e75a04318013e9dbe3d894be691927d27dc2fe53fddc0 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Sandboxed Containers 1.1 | unaffected sha256:24722900db1425bf0c27f6ad6f3fb7d79ff9ebc433bdab58423fa71bab76122b * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Sandboxed Containers 1.1 | unaffected sha256:9ff002e628e5646b5ab3cc9201087847bea29569b4a1bc135b89d5c1a5f0a422 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Sandboxed Containers 1.1 | unaffected sha256:8f29671308ca658e32e97d5c3b482f7541aae1bca1b71f39b3276a9a334d8108 * rpm | Not specified |
| CNA | Red Hat | Red Hat OpenShift Sandboxed Containers 1.1 | unaffected sha256:59fb1f7f1653361d94f7d48b42d8fe19ed3263c1c78654837c11f2135544c1ac * rpm | Not specified |
| ADP | Siemens | RUGGEDCOM ROX MX5000 | affected V2.17.1 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX MX5000RE | affected V2.17.1 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1400 | affected V2.17.1 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1500 | affected V2.17.1 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1501 | affected V2.17.1 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1510 | affected V2.17.1 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1511 | affected V2.17.1 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1512 | affected V2.17.1 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1524 | affected V2.17.1 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1536 | affected V2.17.1 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX5000 | affected V2.17.1 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2025:20181 | [email protected] | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2025-6020 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:10357 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:0934 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:10362 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:10027 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:21885 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:15709 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:18219 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:10359 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:10358 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:11487 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:10735 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:10354 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:10361 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:16524 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:10024 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:17181 | [email protected] | access.redhat.com | |
| cert-portal.siemens.com/productcert/html/ssa-577017.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| access.redhat.com/errata/RHSA-2025:10180 | [email protected] | access.redhat.com | |
| www.openwall.com/lists/oss-security/2025/06/17/1 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| lists.debian.org/debian-lts-announce/2025/09/msg00021.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2025:14557 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:11386 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:15828 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:9526 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:10823 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:15099 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:15827 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:22019 | [email protected] | access.redhat.com | |
| github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Red Hat would like to thank Olivier BAL-PETRE (ANSSI - French Cybersecurity Agency) for reporting this issue. (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2025-06-12T16:33:01.214Z | Reported to Red Hat. |
| CNA | 2025-06-17T00:00:00.000Z | Made public. |
Workarounds
CNA: Disable the `pam_namespace` module if it is not essential for your environment, or carefully review and configure it to avoid operating on any directories or paths that can be influenced or controlled by unprivileged users, such as user home directories or world-writable locations like `/tmp`.
There are currently no legacy QID mappings associated with this CVE.