Permissions, Privileges, and Access Controls in systemd - CVE-2025-4598
Published: June 11, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists in systemd-coredump when handling process crashes. A local user who can force a SUID process to crash can replace it with a non-SUID binary to access the original's privileged process coredump and read sensitive data, such as /etc/shadow content, loaded by the original process.
Affected software
systemd-container
systemd-debuginfo
systemd-debugsource
systemd-devel
systemd-journal-remote
systemd-libs
systemd-udev
systemd-udev-compat
systemd-help
systemd (Ubuntu package)
libsystemd0-64bit
nss-mymachines-64bit
libudev-devel-64bit
systemd-64bit-debuginfo
systemd-lang
nss-mymachines-32bit-debuginfo
libudev1-32bit-debuginfo
systemd-32bit
nss-myhostname-32bit
libudev1-32bit
libsystemd0-32bit-debuginfo
nss-mymachines-32bit
libsystemd0-32bit
systemd-32bit-debuginfo
nss-myhostname-32bit-debuginfo
libudev-devel-32bit
libsystemd0
udev-debuginfo
systemd-mini-container-debuginfo
libsystemd0-mini-debuginfo
udev
libudev-mini1-debuginfo
systemd-coredump
nss-myhostname
systemd-container-debuginfo
systemd-mini-debuginfo
nss-mymachines-64bit-debuginfo
libudev1-64bit
nss-myhostname-64bit-debuginfo
libsystemd0-64bit-debuginfo
nss-myhostname-64bit
libudev1-64bit-debuginfo
systemd-64bit
udev-mini-debuginfo
libudev1-debuginfo
nss-systemd
systemd-sysvinit
libsystemd0-debuginfo
systemd-coredump-debuginfo
systemd-mini
libudev1
nss-systemd-debuginfo
systemd-mini-debugsource
systemd-mini-container
systemd-portable
systemd-doc
nss-mymachines
nss-resolve
systemd-network-debuginfo
nss-mymachines-debuginfo
systemd-mini-sysvinit
libudev-mini-devel
nss-myhostname-debuginfo
systemd-journal-remote-debuginfo
systemd-logger
systemd-portable-debuginfo
libudev-devel
systemd-network
libsystemd0-mini
libudev-mini1
udev-mini
nss-resolve-debuginfo
systemd-mini-devel
systemd-mini-doc
systemd-experimental-debuginfo
systemd-experimental
systemd-testsuite
systemd-testsuite-debuginfo
systemd-cryptsetup
systemd-networkd
systemd-nspawn
systemd-pam
systemd-resolved
systemd-timesyncd
systemd (Debian package)
systemd (Red Hat package)
systemd-standalone-repart
systemd-battery-check
systemd-boot-unsigned
systemd-bsod
systemd-pcrlock
systemd-rpm-macros
systemd-standalone-shutdown
systemd-standalone-sysusers
systemd-standalone-tmpfiles
systemd-storagetm
systemd-tests
systemd-oomd-defaults
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
DataStax Hyper-Converged Database
DataStage on Cloud Pak for Data
Cloud Pak for Data System - Cyclops
Oracle Communications Cloud Native Core Console
AppDynamics NodeJS Agent
OpenShift Virtualization
IBM CICS TX Advanced
How to mitigate CVE-2025-4598
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
AppDynamics NodeJS Agent - update to 25.12.1
OpenShift Virtualization - update to 4.19.17
IBM CICS TX Advanced - update to 10.1.0.0 ifix42
Cloud Pak for Data System - Cyclops - update to 11.3.1.1
systemd-container - addressed in versions 243-85, 249-103, 255-44
systemd - addressed in versions 243-85, 249-103, 255-44
systemd-debuginfo - addressed in versions 243-85, 249-103, 255-44
systemd-debugsource - addressed in versions 243-85, 249-103, 255-44
systemd-devel - addressed in versions 243-85, 249-103, 255-44
systemd-journal-remote - update to 243-85
systemd-libs - addressed in versions 243-85, 249-103, 255-44
systemd-udev - addressed in versions 243-85, 249-103, 255-44
systemd-udev-compat - update to 243-85
systemd-help - addressed in versions 243-85, 249-103, 255-44
systemd (Ubuntu package) - addressed in versions 245.4-4ubuntu3.24+esm1, 249.11-0ubuntu3.16, 255.4-1ubuntu8.8, 256.5-2ubuntu3.3, 257.4-1ubuntu3.1
libsystemd0-64bit - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-mymachines-64bit - update to 246.16-150300.7.60.1
libudev-devel-64bit - update to 246.16-150300.7.60.1
systemd-64bit-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-lang - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-mymachines-32bit-debuginfo - update to 246.16-150300.7.60.1
libudev1-32bit-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-32bit - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-myhostname-32bit - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
libudev1-32bit - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
libsystemd0-32bit-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-mymachines-32bit - update to 246.16-150300.7.60.1
libsystemd0-32bit - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-32bit-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-myhostname-32bit-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
libudev-devel-32bit - update to 246.16-150300.7.60.1
libsystemd0 - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
udev-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-mini-container-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
libsystemd0-mini-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
udev - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
libudev-mini1-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
systemd-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-coredump - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-myhostname - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-container-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-mini-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
systemd-journal-remote - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-mymachines-64bit-debuginfo - update to 246.16-150300.7.60.1
libudev1-64bit - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-myhostname-64bit-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
libsystemd0-64bit-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-myhostname-64bit - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
libudev1-64bit-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-64bit - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
udev-mini-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
libudev1-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-systemd - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-sysvinit - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
libsystemd0-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-coredump-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-mini - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
libudev1 - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-systemd-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-container - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-mini-debugsource - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
systemd-mini-container - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
systemd-portable - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-doc - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-mymachines - update to 246.16-150300.7.60.1
nss-resolve - update to 246.16-150300.7.60.1
systemd-network-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
nss-mymachines-debuginfo - update to 246.16-150300.7.60.1
systemd-mini-sysvinit - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
systemd - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
libudev-mini-devel - update to 246.16-150300.7.60.1
nss-myhostname-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-journal-remote-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-logger - update to 246.16-150300.7.60.1
systemd-portable-debuginfo - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
libudev-devel - update to 246.16-150300.7.60.1
systemd-network - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-debugsource - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
systemd-devel - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.2
libsystemd0-mini - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
libudev-mini1 - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
udev-mini - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
nss-resolve-debuginfo - update to 246.16-150300.7.60.1
systemd-mini-devel - addressed in versions 246.16-150300.7.60.1, 249.17-150400.8.49.1
systemd-mini-doc - update to 249.17-150400.8.49.1
systemd-experimental-debuginfo - update to 249.17-150400.8.49.2
systemd-experimental - update to 249.17-150400.8.49.2
systemd-testsuite - update to 249.17-150400.8.49.2
systemd-testsuite-debuginfo - update to 249.17-150400.8.49.2
systemd-cryptsetup - addressed in versions 249-103, 255-44
systemd-networkd - addressed in versions 249-103, 255-44
systemd-nspawn - addressed in versions 249-103, 255-44
systemd-pam - addressed in versions 249-103, 255-44
systemd-resolved - addressed in versions 249-103, 255-44
systemd-timesyncd - addressed in versions 249-103, 255-44
systemd (Debian package) - update to 252.38-1~deb12u1
systemd (Red Hat package) - update to 252-55.el9_7.7
systemd-standalone-repart - update to 255-7
systemd - update to 255-7
systemd-battery-check - update to 255-7
systemd-boot-unsigned - update to 255-7
systemd-bsod - update to 255-7
systemd-container - update to 255-7
systemd-devel - update to 255-7
systemd-journal-remote - update to 255-7
systemd-libs - update to 255-7
systemd-pam - update to 255-7
systemd-pcrlock - update to 255-7
systemd-rpm-macros - update to 255-7
systemd-resolved - update to 255-7
systemd-standalone-shutdown - update to 255-7
systemd-standalone-sysusers - update to 255-7
systemd-standalone-tmpfiles - update to 255-7
systemd-storagetm - update to 255-7
systemd-tests - update to 255-7
systemd-udev - update to 255-7
systemd-doc - update to 255-7
systemd-oomd-defaults - update to 255-7
systemd - addressed in versions 256.15-1.fc41, 257.4-5.fc42
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Privilege escalation in systemd
- Debian update for systemd
- Ubuntu update for systemd
- Fedora 42 update for systemd
- Fedora 41 update for systemd
- SUSE update for systemd
- openEuler 24.03 LTS SP1 update for systemd
- openEuler 24.03 LTS update for systemd
- openEuler 22.03 LTS SP4 update for systemd
- openEuler 22.03 LTS SP3 update for systemd
- openEuler 24.03 LTS SP2 update for systemd
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Console
- openEuler 20.03 LTS SP4 update for systemd
- SUSE update for systemd
- Multiple vulnerabilities in IBM CICS TX Advanced
- Anolis OS update for systemd
- Red Hat Enterprise Linux 9 update for systemd
- Multiple vulnerabilities in OpenShift Virtualization 4.19
- Splunk AppDynamics NodeJS Agent update for third-party components
- Multiple vulnerabilities in IBM DataStax Hyper-Converged Database
- Multiple vulnerabilities in IBM Cloud Pak for Data System - Cyclops
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data