CVE-2025-4598
published 2025-05-30CVE-2025-4598: A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access…
PriorityP425medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EPSS
0.66%
47.5th percentile
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.
A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | systemd | < systemd 252.38-1~deb12u1 (bookworm) | systemd 252.38-1~deb12u1 (bookworm) |
| linux | linux_kernel | < 6.16 | 6.16 |
| msrc | azl3_kernel_6.6.96.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_systemd_255-22_on_azure_linux_3.0 | — | — |
| msrc | azl3_systemd_255-23_on_azure_linux_3.0 | — | — |
| msrc | azl3_systemd_255-24_on_azure_linux_3.0 | — | — |
| msrc | cbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_systemd_250.3-22_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_systemd_250.3-23_on_cbl_mariner_2.0 | — | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| systemd_project | systemd | < 252.37 | 252.37 |
| systemd_project | systemd | >= 0 < 247.3-7+deb11u7 | 247.3-7+deb11u7 |
| systemd_project | systemd | >= 0 < 252.38-1~deb12u1 | 252.38-1~deb12u1 |
| systemd_project | systemd | >= 0 < 257.6-1 | 257.6-1 |
| systemd_project | systemd | >= 0 < 257.6-1 | 257.6-1 |
| systemd_project | systemd | >= 253 < 253.32 | 253.32 |
| systemd_project | systemd | >= 254 < 254.25 | 254.25 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_oracle4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (systemd) — CVE-2025-4598
vendor_oracle·2025-07-15·CVSS 4.7
CVE-2025-4598 [MEDIUM] Oracle Oracle Communications Risk Matrix: Configuration (systemd) — CVE-2025-4598
Oracle Oracle Communications Risk Matrix: Configuration (systemd) vulnerability
CVE: CVE-2025-4598
CVSS: 4.7
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
Ubuntu
systemd vulnerability
vendor_ubuntu·2025-06-09
CVE-2025-4598 systemd vulnerability
Title: systemd vulnerability
Summary: systemd could be made to leak sensitive information.
Qualys discovered that systemd incorrectly handled metadata when processing
application crashes. An attacker could possibly use this issue to expose
sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
systemd-coredump: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump
vendor_redhat·2025-05-29·CVSS 4.7
CVE-2025-4598 [MEDIUM] CWE-364 systemd-coredump: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump
systemd-coredump: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.
A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and fo
Microsoft
Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump
vendor_msrc·2025-05-13·CVSS 4.7
CVE-2025-4598 [MEDIUM] CWE-364 Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump
Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer A
Debian
CVE-2025-4598: systemd - A vulnerability was found in systemd-coredump. This flaw allows an attacker to f...
vendor_debian·2025·CVSS 4.7
CVE-2025-4598 [MEDIUM] CVE-2025-4598: systemd - A vulnerability was found in systemd-coredump. This flaw allows an attacker to f...
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the r
GHSA
GHSA-jx2m-wgq5-5qcj: A vulnerability was found in systemd-coredump
ghsa_unreviewed·2025-05-30
CVE-2025-4598 [MEDIUM] CWE-364 GHSA-jx2m-wgq5-5qcj: A vulnerability was found in systemd-coredump
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.
A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the
OSV
CVE-2025-4598: A vulnerability was found in systemd-coredump
osv·2025-05-30·CVSS 4.7
CVE-2025-4598 [MEDIUM] CVE-2025-4598: A vulnerability was found in systemd-coredump
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the r
No detection rules found.
No public exploits indexed.
Schneier
New Linux Vulnerabilities
blogs_schneier·2025-06-03·CVSS 4.7
CVE-2025-5054 [MEDIUM] New Linux Vulnerabilities
## New Linux Vulnerabilities
They’re interesting :
Tracked as CVE-2025-5054 and CVE-2025-4598 , both vulnerabilities are race condition bugs that could enable a local attacker to obtain access to access sensitive information. Tools like Apport and systemd-coredump are designed to handle crash reporting and core dumps in Linux systems.
[…]
“This means that if a local attacker manages to induce a crash in a privileged process and quickly replaces it with another one with the same process ID that resides inside a mount and pid namespace, apport will attempt to forward the core dump (which might contain sensitive information belonging to the original, privileged process) into the namespace.”
Moderate severity, but definitely worth fixing.
Slashdot thread .
Tags: Linux , passwords , vuln
Qualys
Qualys TRU Discovers Two Local Information Disclosure Vulnerabilities in Apport and systemd-coredump: CVE-2025-5054 and CVE-2025-4598 | Qualys
blogs_qualys·2025-05-29·CVSS 4.7
CVE-2025-5054 [MEDIUM] Qualys TRU Discovers Two Local Information Disclosure Vulnerabilities in Apport and systemd-coredump: CVE-2025-5054 and CVE-2025-4598 | Qualys
#### Table of Contents
- What is systemd-coredump and Apport (Crash Reporting on Linux)?
- Technical Details
- Qualys QID Coverage
- Leverage Qualys TruRisk Eliminate to Mitigate These Risks
The Qualys Threat Research Unit (TRU) has discovered two local information-disclosure vulnerabilities in Apport and systemd-coredump.
Both issues are race-condition vulnerabilities. The first (CVE-2025-5054) affects Ubuntu’s core-dump handler, Apport, and the second (CVE-2025-4598) targets systemd-coredump, which is the default core-dump handler on Red Hat Enterprise Linux 9 and the recently released 10, as well as on Fedora. These race conditions allow a local attacker to exploit a SUID program and gain read access to the resulting core dump.
Qualys TRU has developed proofs of concept (POCs) for c
Qualys
Qualys TRU Discovers Two Local Information Disclosure Vulnerabilities in Apport and systemd-coredump: CVE-2025-5054 and CVE-2025-4598
blogs_qualys·2025-05-29·CVSS 4.7
CVE-2025-5054 [MEDIUM] Qualys TRU Discovers Two Local Information Disclosure Vulnerabilities in Apport and systemd-coredump: CVE-2025-5054 and CVE-2025-4598
## Table of Contents
What is systemd-coredump and Apport (Crash Reporting on Linux)?
Technical Details
Qualys QID Coverage
Leverage Qualys TruRisk Eliminate to Mitigate These Risks
The Qualys Threat Research Unit (TRU) has discovered two local information-disclosure vulnerabilities in Apport and systemd-coredump.
Both issues are race-condition vulnerabilities. The first (CVE-2025-5054) affects Ubuntu’s core-dump handler, Apport , and the second (CVE-2025-4598) targets systemd-coredump , which is the default core-dump handler on Red Hat Enterprise Linux 9 and the recently released 10, as well as on Fedora. These race conditions allow a local attacker to exploit a SUID program and gain read access to the resulting core dump.
Qualys TRU has developed proofs of concept (POCs) for certai
Bugzilla
CVE-2025-4598 systemd-coredump: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump
bugzilla·2025-05-29·CVSS 4.7
CVE-2025-4598 [MEDIUM] CVE-2025-4598 systemd-coredump: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump
CVE-2025-4598 systemd-coredump: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump
A race condidition in systemd-coredump allows a local attacker to crash a SUID program and gain read access to the resulting core dump
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:22660 https://access.redhat.com/errata/RHSA-2025:22660
---
This race condition in systemd-coredump is particularly concerning, as it allows a local attacker not only to crash a SUID program but also to gain unauthorized read access to the generated core dump. This could potentially expose sensitive information such as credentials or memory contents, increasing the overall security risk. https://ba
Bugzilla
CVE-2025-4598 rpm-ostree: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump [fedora-42]
bugzilla·2025-05-29·CVSS 4.7
CVE-2025-4598 [MEDIUM] CVE-2025-4598 rpm-ostree: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump [fedora-42]
CVE-2025-4598 rpm-ostree: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2369242
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug wi
https://access.redhat.com/errata/RHSA-2025:22660https://access.redhat.com/errata/RHSA-2025:22868https://access.redhat.com/errata/RHSA-2025:23227https://access.redhat.com/errata/RHSA-2025:23234https://access.redhat.com/errata/RHSA-2026:0414https://access.redhat.com/errata/RHSA-2026:1652https://access.redhat.com/errata/RHSA-2026:18153https://access.redhat.com/security/cve/CVE-2025-4598https://bugzilla.redhat.com/show_bug.cgi?id=2369242https://www.openwall.com/lists/oss-security/2025/05/29/3http://seclists.org/fulldisclosure/2025/Jun/9http://www.openwall.com/lists/oss-security/2025/06/05/1http://www.openwall.com/lists/oss-security/2025/06/05/3http://www.openwall.com/lists/oss-security/2025/08/18/3https://blogs.oracle.com/linux/post/analysis-of-cve-2025-4598https://ciq.com/blog/the-real-danger-of-systemd-coredump-cve-2025-4598/https://lists.debian.org/debian-lts-announce/2025/07/msg00022.htmlhttps://www.openwall.com/lists/oss-security/2025/08/18/3https://cert-portal.siemens.com/productcert/html/ssa-082556.html
2025-05-30
Published