PT-2025-25774 · Linux+1 · Linux+1

Alexander Bergmann

·

Published

2025-06-17

·

Updated

2026-05-16

·

CVE-2025-6018

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux PAM pam-config (affected versions not specified)
Description A Local Privilege Escalation (LPE) flaw exists in pam-config within Linux Pluggable Authentication Modules (PAM). This issue allows an unprivileged local attacker, such as one connected via SSH, to acquire elevated privileges typically reserved for a physically present user with "allow active" status. Consequently, the attacker may perform Polkit actions marked as "allow active yes", which are generally restricted to console users, potentially leading to unauthorized control over system configurations, services, or other sensitive operations. Additionally, the Udisks component of the Linux-PAM authentication module may be affected by configuration errors that could allow an attacker to gain root privileges via SSH.
Recommendations Update pam-config to stop adding pam env in the AUTH stack and ensure this module is placed at the end of the SESSION stack. Update pam to change the default behavior of pam env to not read the user .pam environment file. Update pam to ensure pam namespace functions operate on file descriptors instead of absolute paths when dealing with user-controlled paths.

Exploit

Fix

DoS

LPE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07575
CVE-2025-6018
OPENSUSE-SU-2025:15219-1
OPENSUSE-SU-2025:15257-1
SUSE-RU-2025:20479-1
SUSE-SU-2025:02001-1
SUSE-SU-2025:02002-1
SUSE-SU-2025:02003-1
SUSE-SU-2025:02004-1
SUSE-SU-2025:02005-1
SUSE-SU-2025:02013-1
SUSE-SU-2025:02015-1
SUSE-SU-2025:02026-1
SUSE-SU-2025:02031-1
SUSE-SU-2025:02032-1
SUSE-SU-2025:02080-1
SUSE-SU-2025:02081-1
SUSE-SU-2025:02082-1
SUSE-SU-2025:20496-1
SUSE-SU-2025:20513-1
SUSE-SU-2025:20533-1
SUSE-SU-2025_02001-1
SUSE-SU-2025_02002-1
SUSE-SU-2025_02003-1
SUSE-SU-2025_02004-1
SUSE-SU-2025_02005-1
SUSE-SU-2025_02013-1
SUSE-SU-2025_02015-1
SUSE-SU-2025_02026-1
SUSE-SU-2025_02031-1
SUSE-SU-2025_02032-1
SUSE-SU-2025_02080-1
SUSE-SU-2025_02081-1
SUSE-SU-2025_02082-1

Affected Products

Linux
Suse