Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-4598— Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump

Quick assessment

Affected
CVE-2025-4598
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux systemd-coredump是Linux基金会的一个系统服务, 它能从操作系统内核中获取内存转储,并能对获取到的数据进行各种处理。 Linux systemd-coredump存在安全漏洞,该漏洞源于竞争条件,可能导致敏感数据泄露。

CVSS 4.7 · Medium EPSS 0.77% · P53

Affected Version Matrix 23

VendorProduct Version RangeStatus
None None < 252.37 affected
253.0< 253.32 affected
254.0< 254.25 affected
255.0< 255.19 affected
256.0< 256.14 affected
257.0< 257.6 affected
Red Hat Red Hat Ceph Storage 7 7< * unaffected
Red Hat Red Hat Ceph Storage 8 8< * unaffected
1769512383< * unaffected
Red Hat Red Hat Discovery 2 1767888970< * unaffected
1767904573< * unaffected
Red Hat Red Hat Enterprise Linux 10 0:257-23.el10< * unaffected
any unaffected
any unaffected
Red Hat Red Hat Enterprise Linux 7 any unaffected
any affected
Red Hat Red Hat Enterprise Linux 8 any affected
Red Hat Red Hat Enterprise Linux 9 0:252-55.el9_7.7< * unaffected
0:252-55.el9_7.7< * unaffected
any unaffected
Red Hat Red Hat Insights proxy 1.5 1.5.9-1765201856< * unaffected
Red Hat Red Hat OpenShift Container Platform 4 any affected
any unaffected

I. Basic Information for CVE-2025-4598

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信号处理例程中的竞争条件
Source: CVE Program / CVE List V5
Vulnerability Title
Linux systemd-coredump 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux systemd-coredump是Linux基金会的一个系统服务, 它能从操作系统内核中获取内存转储,并能对获取到的数据进行各种处理。 Linux systemd-coredump存在安全漏洞,该漏洞源于竞争条件,可能导致敏感数据泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 0 ~ 252.37 -
Red Hat Red Hat Enterprise Linux 10 0:257-23.el10 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 9 0:252-55.el9_7.7 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:252-55.el9_7.7 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Ceph Storage 7 7 ~ * cpe:/a:redhat:ceph_storage:7::el9
Red Hat Red Hat Ceph Storage 8 8 ~ * cpe:/a:redhat:ceph_storage:8::el9
Red Hat Red Hat Ceph Storage 8 1769512383 ~ * cpe:/a:redhat:ceph_storage:8::el9
Red Hat Red Hat Discovery 2 1767888970 ~ * cpe:/a:redhat:discovery:2::el9
Red Hat Red Hat Discovery 2 1767904573 ~ * cpe:/a:redhat:discovery:2::el9
Red Hat Red Hat Insights proxy 1.5 1.5.9-1765201856 ~ * cpe:/a:redhat:insights_proxy:1.5::el9
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2025-4598

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-4598

登录查看更多情报信息。

Vendor Advisories for CVE-2025-4598 (8)

IV. Related Vulnerabilities

V. Comments for CVE-2025-4598

No comments yet


Leave a comment