CVE-2025-6020
published 2025-06-17CVE-2025-6020: A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.40%
32.3th percentile
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.5.2-6+deb12u2 (bookworm) | pam 1.5.2-6+deb12u2 (bookworm) |
| debian | pam | — | — |
| msrc | azl3_pam_1.5.3-5_on_azure_linux_3.0 | — | — |
| msrc | cbl2_pam_1.5.1-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_pam_1.5.1-8_on_cbl_mariner_2.0 | — | — |
| pam | pam | >= 0 < 1.4.0-9+deb11u2 | 1.4.0-9+deb11u2 |
| pam | pam | >= 0 < 1.5.2-6+deb12u2 | 1.5.2-6+deb12u2 |
| pam | pam | >= 0 < 1.7.0-5 | 1.7.0-5 |
| pam | pam | >= 0 < 1.7.0-5 | 1.7.0-5 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
linux-pam: Incomplete fix for CVE-2025-6020
vendor_redhat·2025-08-13·CVSS 7.8
CVE-2025-8941 [HIGH] CWE-22 linux-pam: Incomplete fix for CVE-2025-6020
linux-pam: Incomplete fix for CVE-2025-6020
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
Statement: This vulnerability in pam_namespace is rated Important because it allows a local, unprivileged user to escalate privileges to root by exploiting symlink attacks or race conditions in polyinstantiated directories under thei
Ubuntu
PAM vulnerability
vendor_ubuntu·2025-06-18
CVE-2025-6020 PAM vulnerability
Title: PAM vulnerability
Summary: PAM could be made to run programs as an administrator.
Olivier BAL-PETRE discovered that the PAM pam_namespace module incorrectly
handled user-controlled paths. In environments where pam_namespace is used,
a local attacker could possibly use this issue to escalate their privileges
to root.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
linux-pam: Linux-pam directory Traversal
vendor_redhat·2025-06-17·CVSS 7.8
CVE-2025-6020 [HIGH] CWE-22 linux-pam: Linux-pam directory Traversal
linux-pam: Linux-pam directory Traversal
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
Statement: This vulnerability in pam_namespace marked as Important rather than Moderate due to its direct impact on privilege boundaries and the ease of exploitation in common configurations. By leveraging symlink attacks or race conditions in polyinstantiated directories under their control, unprivil
Microsoft
Linux-pam: linux-pam directory traversal
vendor_msrc·2025-06-10·CVSS 7.8
CVE-2025-6020 [HIGH] CWE-22 Linux-pam: linux-pam directory traversal
Linux-pam: linux-pam directory traversal
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.co
Debian
CVE-2025-8941: pam - A flaw was found in linux-pam. The pam_namespace module may improperly handle us...
vendor_debian·2025·CVSS 7.8
CVE-2025-8941 [HIGH] CVE-2025-8941: pam - A flaw was found in linux-pam. The pam_namespace module may improperly handle us...
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
Scope: local
bookworm: undetermined
bullseye: undetermined
forky: undetermined
sid: undetermined
trixie: undetermined
Debian
CVE-2025-6020: pam - A flaw was found in linux-pam. The module pam_namespace may use access user-cont...
vendor_debian·2025·CVSS 7.8
CVE-2025-6020 [HIGH] CVE-2025-6020: pam - A flaw was found in linux-pam. The module pam_namespace may use access user-cont...
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
Scope: local
bookworm: resolved (fixed in 1.5.2-6+deb12u2)
bullseye: resolved (fixed in 1.4.0-9+deb11u2)
forky: resolved (fixed in 1.7.0-5)
sid: resolved (fixed in 1.7.0-5)
trixie: resolved (fixed in 1.7.0-5)
GHSA
GHSA-hqqx-rjqh-53c2: A flaw was found in linux-pam
ghsa_unreviewed·2025-08-13·CVSS 7.8
CVE-2025-8941 [HIGH] CWE-22 GHSA-hqqx-rjqh-53c2: A flaw was found in linux-pam
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
OSV
CVE-2025-8941: A flaw was found in linux-pam
osv·2025-08-13·CVSS 7.8
CVE-2025-8941 [HIGH] CVE-2025-8941: A flaw was found in linux-pam
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
OSV
CVE-2025-6020: A flaw was found in linux-pam
osv·2025-06-17·CVSS 7.8
CVE-2025-6020 [HIGH] CVE-2025-6020: A flaw was found in linux-pam
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-8941 linux-pam: Incomplete fix for CVE-2025-6020
bugzilla·2025-08-13·CVSS 7.8
CVE-2025-8941 [HIGH] CVE-2025-8941 linux-pam: Incomplete fix for CVE-2025-6020
CVE-2025-8941 linux-pam: Incomplete fix for CVE-2025-6020
CVE-2025-8941 – this is the “complete” fix for CVE-2025-6020, a directory-traversal privilege escalation in Linux-PAM’s pam_namespace module. The upstream patch fully addresses the symlink and race-condition attack vectors that were previously mitigated only partially.
Discussion:
Hi
The description is not fully clear about that: Is this CVE for a Red Hat specific incomplte fix? The description above say "The upstream patch fully addresses the symlink and race-condition attack vectors that were previously mitigated only partially." so this sound that upstream was fine at every point in time with the patches and the CVE is specific for a Red Hat update for CVE-2025-6020? Can you please clarify?
Regards,
Salvatore
---
This issu
Bugzilla
CVE-2025-6020 linux-pam: Linux-pam directory Traversal
bugzilla·2025-06-12·CVSS 7.8
CVE-2025-6020 [HIGH] CVE-2025-6020 linux-pam: Linux-pam directory Traversal
CVE-2025-6020 linux-pam: Linux-pam directory Traversal
The module pam_namespace in linux-pam <= 1.7.0 may access user-controlled paths without proper protections, which allows a local user to elevate their privileges to root via multiple symlink attacks and race conditions.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:9526 https://access.redhat.com/errata/RHSA-2025:9526
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.4 Extended Update Support
Via RHSA-2025:10024 https://access.redhat.com/errata/RHSA-2025:10024
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:10027 https://access.redhat.com/errata/RHSA-2025:10027
---
Thi
https://access.redhat.com/errata/RHSA-2025:10024https://access.redhat.com/errata/RHSA-2025:10027https://access.redhat.com/errata/RHSA-2025:10180https://access.redhat.com/errata/RHSA-2025:10354https://access.redhat.com/errata/RHSA-2025:10357https://access.redhat.com/errata/RHSA-2025:10358https://access.redhat.com/errata/RHSA-2025:10359https://access.redhat.com/errata/RHSA-2025:10361https://access.redhat.com/errata/RHSA-2025:10362https://access.redhat.com/errata/RHSA-2025:10735https://access.redhat.com/errata/RHSA-2025:10823https://access.redhat.com/errata/RHSA-2025:11386https://access.redhat.com/errata/RHSA-2025:11487https://access.redhat.com/errata/RHSA-2025:14557https://access.redhat.com/errata/RHSA-2025:15099https://access.redhat.com/errata/RHSA-2025:15709https://access.redhat.com/errata/RHSA-2025:15827https://access.redhat.com/errata/RHSA-2025:15828https://access.redhat.com/errata/RHSA-2025:16524https://access.redhat.com/errata/RHSA-2025:17181https://access.redhat.com/errata/RHSA-2025:18219https://access.redhat.com/errata/RHSA-2025:20181https://access.redhat.com/errata/RHSA-2025:21885https://access.redhat.com/errata/RHSA-2025:22019https://access.redhat.com/errata/RHSA-2025:9526https://access.redhat.com/errata/RHSA-2026:0934https://access.redhat.com/security/cve/CVE-2025-6020https://bugzilla.redhat.com/show_bug.cgi?id=2372512https://github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gxhttp://www.openwall.com/lists/oss-security/2025/06/17/1https://lists.debian.org/debian-lts-announce/2025/09/msg00021.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-577017.html
2025-06-17
Published