Linux-pam: incomplete fix for cve-2025-6020

  1. Description
  2. References

Description

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a “complete” fix for CVE-2025-6020.

References

https://www.cve.org/CVERecord?id=CVE-2025-8941


转载请注明来源,欢迎对文章中的引用来源进行考证,欢迎指出任何有错误或不够清晰的表达。可以在下面评论区评论.

文章标题:Linux-pam: incomplete fix for cve-2025-6020

本文作者:wangzhirui

发布时间:2025-11-22, 17:15:15

原始链接:https://wangzhirui.com/2025/11/22/Linux-pam-incomplete-fix-for-cve-2025-6020/

版权声明: "署名-非商用-相同方式共享 4.0" 转载请保留原文链接及作者。

时刻