Input validation error in libcap - CVE-2025-1390
Published: February 25, 2025
Vulnerability details
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input when parsing groups names. The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. A local user can use this vulnerability to escalate privileges on systems where "/etc/security/capability.conf" is used to configure user inherited privileges by constructing specific usernames.
Affected software
Anolis OS
openEuler
Ubuntu
IBM Automation Decision Services
libpam-cap (Ubuntu package)
libcap
libcap-devel
libcap-static
libcap-debuginfo
libcap-debugsource
libcap-help
How to mitigate CVE-2025-1390
libpam-cap (Ubuntu package) - addressed in versions 1:2.32-1ubuntu0.2, 1:2.44-1ubuntu0.22.04.2, 1:2.66-5ubuntu2.2, 1:2.66-5ubuntu3.1
libcap - addressed in versions 2.48-6.0.2, 2.69-3
libcap-devel - addressed in versions 2.48-6.0.2, 2.69-3
libcap-static - update to 2.69-3
libcap - update to 2.69-4
libcap-debuginfo - update to 2.69-4
libcap-debugsource - update to 2.69-4
libcap-devel - update to 2.69-4
libcap-help - update to 2.69-4