CVE Watchtower

← Back to CVE List

CVE-2025-4598NVD

Vulnerability Summary

A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.

A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.
Severity Level
MEDIUM(4.7)
Published Date
May 30, 2025
Last Modified
Sep 1, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
1.20%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics — Score 4.7 (MEDIUM)
Attack VectorLocal
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityNone
AvailabilityNone

Affected & Patched Versions

Affected Versions
  • Systemd Project Systemd < 252.37
  • Systemd Project Systemd >= 253 and < 253.32
  • Systemd Project Systemd >= 254 and < 254.25
  • Systemd Project Systemd >= 255 and < 255.19
  • Systemd Project Systemd >= 256 and < 256.14
  • Systemd Project Systemd >= 257 and < 257.6
  • Redhat Openshift Container Platform
  • Redhat Enterprise Linux
  • Debian Debian Linux
  • Oracle Linux
  • Linux Linux Kernel < 6.16
Patched Versions
  • Systemd Project Systemd 252.37
  • Systemd Project Systemd 253.32
  • Systemd Project Systemd 254.25
  • Systemd Project Systemd 255.19
  • Systemd Project Systemd 256.14
  • Systemd Project Systemd 257.6
  • Linux Linux Kernel 6.16
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.