PT-2025-25774 · Linux+1 · Linux+1
Alexander Bergmann
·
Published
2025-06-17
·
Updated
2026-05-16
·
CVE-2025-6018
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux PAM pam-config (affected versions not specified)
Description
A Local Privilege Escalation (LPE) flaw exists in pam-config within Linux Pluggable Authentication Modules (PAM). This issue allows an unprivileged local attacker, such as one connected via SSH, to acquire elevated privileges typically reserved for a physically present user with "allow active" status. Consequently, the attacker may perform Polkit actions marked as "allow active yes", which are generally restricted to console users, potentially leading to unauthorized control over system configurations, services, or other sensitive operations. Additionally, the Udisks component of the Linux-PAM authentication module may be affected by configuration errors that could allow an attacker to gain root privileges via SSH.
Recommendations
Update pam-config to stop adding
pam env in the AUTH stack and ensure this module is placed at the end of the SESSION stack.
Update pam to change the default behavior of pam env to not read the user .pam environment file.
Update pam to ensure pam namespace functions operate on file descriptors instead of absolute paths when dealing with user-controlled paths.Exploit
Fix
DoS
LPE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux
Suse