Key Linux Systems May Have Security Flaws Which Allow Password Theft
9 Articles
9 Articles
The Qualys Threat Research Unit (TRU) has discovered two local vulnerabilities in Apport and Systemd-Coredump that allow information to be disclosed. Both issues are race condition vulnerabilities. The first (CVE-2025-5054) concerns Ubuntu's core dump handler, Apport, and the second (CVE-2025-4598) targets Systemd-Coredump, the standard core dump handler under Red-Hat Enterprise-Linux 9 and the recently released [...] Qualys' article discovers t…
New Linux Vulnerabilities - Schneier on Security
They’re interesting: Tracked as CVE-2025-5054 and CVE-2025-4598, both vulnerabilities are race condition bugs that could enable a local attacker to obtain access to access sensitive information. Tools like Apport and systemd-coredump are designed to handle crash reporting and core dumps in Linux systems. […] “This means that if a local attacker manages to induce a crash in a privileged process and quickly replaces it with another one with the sa…
Several versions of Ubuntu, Fedora and RHEL are vulnerable. B willing actors can crash applications and exploit confidential data. (Sicherheitlcke, Ubuntu)
A race condition vulnerability exists in the core dump program of Ubuntu, RHEL, and Fedora Linux, which can be exploited by local attackers to steal encrypted information such as user password hashes. Ubuntu has released an update to fix the vulnerability, and systems such as Debian that do not install the relevant program by default are not affected.
Coverage Details
Bias Distribution
- 100% of the sources are Center
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage