CVE-2025-4598
MEDIUMDescription
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.
Is your site exposed to CVE-2025-4598?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| systemd_project | systemd |
| systemd_project | systemd |
| systemd_project | systemd |
| systemd_project | systemd |
| systemd_project | systemd |
| systemd_project | systemd |
| redhat | openshift_container_platform |
| redhat | enterprise_linux |
| redhat | enterprise_linux |
| redhat | enterprise_linux |
| redhat | enterprise_linux |
| debian | debian_linux |
| debian | debian_linux |
| oracle | linux |
| oracle | linux |
| linux | linux_kernel |
References
Advisories & Patches
Exploits
Other References
Frequently Asked Questions
What is CVE-2025-4598? +
How severe is CVE-2025-4598? +
What products are affected by CVE-2025-4598? +
How do I check if I'm vulnerable to CVE-2025-4598? +
Related Vulnerabilities
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to …
A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when …
In the Linux kernel, the following vulnerability has been resolved: zram: fix use-after-free in zram_bvec_write_partial() zram_read_page() picks the sync or …
A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does …
Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in …