PT-2025-23285 · Systemd+9 · Systemd-Coredump+10

David Fernandez Gonzalez

·

Published

2025-01-01

·

Updated

2026-05-19

·

CVE-2025-4598

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions systemd-coredump (affected versions not specified) systemd versions prior to 252.38-1~deb12u1
Description A flaw in systemd-coredump allows an attacker to force a SUID process to crash and replace it with a non-SUID binary, giving access to the original's privileged process coredump and allowing the attacker to read sensitive data. This is achieved by winning a race condition, where the attacker forces the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. The attacker can then read sensitive content loaded into memory by the original binary, affecting data confidentiality.
Recommendations For versions prior to 252.38-1deb12u1, upgrade the systemd packages to version 252.38-1deb12u1 or later. As a temporary workaround, consider restricting access to SUID processes to minimize the risk of exploitation. Avoid using the core pattern variable in /proc/sys/kernel/core pattern until the issue is resolved.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALSA-2025:22660
ALT-PU-2025-12177
ALT-PU-2025-7598
AZL-64289
AZL-64292
AZL-66702
AZL-66704
BDU:2025-06694
CVE-2025-4598
DLA-4259-1
DSA-5931-1
ECHO-A417-190B-BD77
INFSA-2025_22660
MGASA-2025-0178
OESA-2025-1738
OESA-2025-1739
OESA-2025-1740
OESA-2025-1741
OESA-2025-1764
OESA-2025-1946
OPENSUSE-SU-2025:15299-1
RHSA-2025:22660
RHSA-2026:18153
SUSE-SU-2025:02019-1
SUSE-SU-2025:02243-1
SUSE-SU-2025:02244-1
SUSE-SU-2025:02675-1
SUSE-SU-2025:20405-1
SUSE-SU-2025:20416-1
SUSE-SU-2025:20554-1
SUSE-SU-2025:20597-1
SUSE-SU-2025_02019-1
SUSE-SU-2025_02243-1
SUSE-SU-2025_02244-1
SUSE-SU-2025_02675-1
USN-7559-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Debian
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Systemd
Systemd-Coredump