Configuration in pam-32bit - CVE-2025-6018
Published: June 19, 2025 / Updated: February 27, 2026
Vulnerability details
The issue may allow a local user to escalate privileges on the system.
The issue exists due an error in the PAM configuration of openSUSE Leap 15 and SUSE Linux Enterprise 15. An unprivileged user who logs in via sshd can force the pam_env module to add arbitrary variables to PAM's environment, leading to arbitrary code execution as root.
Affected software
pam_pkcs11-32bit
pam_pkcs11-debuginfo-32bit
pam_pkcs11
pam_pkcs11-debugsource
pam_pkcs11-debuginfo
pam_pkcs11-32bit-debuginfo
pam_pkcs11-64bit
pam_pkcs11-64bit-debuginfo
pam_pkcs11-devel-doc
pam-debugsource
pam-devel
pam-extra
pam
pam-extra-debuginfo
pam-debuginfo
pam-extra-32bit
pam-extra-debuginfo-32bit
pam-debuginfo-32bit
pam-doc
pam-32bit-debuginfo
pam-extra-32bit-debuginfo
pam-devel-32bit
gdm
libgdm1
libgdm1-debuginfo
gdm-debuginfo
gdm-debugsource
gdm-devel
typelib-1_0-Gdm-1_0
gdmflexiserver
gdm-lang
gdm-systemd
gdm-branding-upstream
gdm-schema
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Desktop Applications Module
Development Tools Module
Basesystem Module
openSUSE Leap
How to mitigate CVE-2025-6018
pam_pkcs11-32bit - addressed in versions 0.6.8-7.13.1, 0.6.10-150100.3.11.1, 0.6.10-150600.16.8.1
pam_pkcs11-debuginfo-32bit - update to 0.6.8-7.13.1
pam_pkcs11 - addressed in versions 0.6.8-7.13.1, 0.6.10-150100.3.11.1, 0.6.10-150600.16.8.1
pam_pkcs11-debugsource - addressed in versions 0.6.8-7.13.1, 0.6.10-150100.3.11.1, 0.6.10-150600.16.8.1
pam_pkcs11-debuginfo - addressed in versions 0.6.8-7.13.1, 0.6.10-150100.3.11.1, 0.6.10-150600.16.8.1
pam_pkcs11-32bit-debuginfo - addressed in versions 0.6.10-150100.3.11.1, 0.6.10-150600.16.8.1
pam_pkcs11-64bit - update to 0.6.10-150600.16.8.1
pam_pkcs11-64bit-debuginfo - update to 0.6.10-150600.16.8.1
pam_pkcs11-devel-doc - update to 0.6.10-150600.16.8.1
pam-debugsource - addressed in versions 1.1.8-24.71.1, 1.3.0-150000.6.83.1
pam-devel - addressed in versions 1.1.8-24.71.1, 1.3.0-150000.6.83.1
pam-extra - addressed in versions 1.1.8-24.71.1, 1.3.0-150000.6.83.1
pam - addressed in versions 1.1.8-24.71.1, 1.3.0-150000.6.83.1
pam-extra-debuginfo - addressed in versions 1.1.8-24.71.1, 1.3.0-150000.6.83.1
pam-debuginfo - addressed in versions 1.1.8-24.71.1, 1.3.0-150000.6.83.1
pam-extra-32bit - addressed in versions 1.1.8-24.71.1, 1.3.0-150000.6.83.1
pam-extra-debuginfo-32bit - update to 1.1.8-24.71.1
pam-debuginfo-32bit - update to 1.1.8-24.71.1
pam-doc - addressed in versions 1.1.8-24.71.1, 1.3.0-150000.6.83.1
pam-32bit-debuginfo - update to 1.3.0-150000.6.83.1
pam-extra-32bit-debuginfo - update to 1.3.0-150000.6.83.1
pam-devel-32bit - update to 1.3.0-150000.6.83.1
gdm - addressed in versions 3.10.0.1-54.23.1, 3.34.1-150200.8.26.1, 41.3-150400.4.14.1, 45.0.1-150600.6.8.1, 45.0.1-150700.12.5.1
libgdm1 - addressed in versions 3.10.0.1-54.23.1, 3.34.1-150200.8.26.1, 41.3-150400.4.14.1, 45.0.1-150600.6.8.1, 45.0.1-150700.12.5.1
libgdm1-debuginfo - addressed in versions 3.10.0.1-54.23.1, 3.34.1-150200.8.26.1, 41.3-150400.4.14.1, 45.0.1-150600.6.8.1, 45.0.1-150700.12.5.1
gdm-debuginfo - addressed in versions 3.10.0.1-54.23.1, 3.34.1-150200.8.26.1, 41.3-150400.4.14.1, 45.0.1-150600.6.8.1, 45.0.1-150700.12.5.1
gdm-debugsource - addressed in versions 3.10.0.1-54.23.1, 3.34.1-150200.8.26.1, 41.3-150400.4.14.1, 45.0.1-150600.6.8.1, 45.0.1-150700.12.5.1
gdm-devel - addressed in versions 3.10.0.1-54.23.1, 3.34.1-150200.8.26.1, 41.3-150400.4.14.1, 45.0.1-150600.6.8.1, 45.0.1-150700.12.5.1
typelib-1_0-Gdm-1_0 - addressed in versions 3.10.0.1-54.23.1, 3.34.1-150200.8.26.1, 41.3-150400.4.14.1, 45.0.1-150600.6.8.1, 45.0.1-150700.12.5.1
gdmflexiserver - addressed in versions 3.10.0.1-54.23.1, 3.34.1-150200.8.26.1, 41.3-150400.4.14.1, 45.0.1-150600.6.8.1, 45.0.1-150700.12.5.1
gdm-lang - addressed in versions 3.10.0.1-54.23.1, 3.34.1-150200.8.26.1, 41.3-150400.4.14.1, 45.0.1-150600.6.8.1, 45.0.1-150700.12.5.1
gdm-systemd - addressed in versions 3.34.1-150200.8.26.1, 41.3-150400.4.14.1, 45.0.1-150600.6.8.1, 45.0.1-150700.12.5.1
gdm-branding-upstream - addressed in versions 41.3-150400.4.14.1, 45.0.1-150600.6.8.1
gdm-schema - addressed in versions 41.3-150400.4.14.1, 45.0.1-150600.6.8.1, 45.0.1-150700.12.5.1
Links to Public Exploits and PoC-codes
- Exploit #12446 - CVE-2025-6018-CVE-2025-6019-Privilege-Escalation-Exploit () (February 27, 2026)
- Exploit #12444 - opensuse-leap-privesc-exploit (Privilege escalation exploit chain (CVE-2025-6018 + CVE-2025-6019) for openSUSE Leap 15.6) (February 27, 2026)
- Exploit #12410 - CVE-2025-6018_Poc (February 13, 2026)
- Exploit #12407 - Exploit-Chain-CVE-2025-6018-6019 (February 13, 2026)
- Exploit #12402 - CVE-2025-6018-CVE-2025-6019-Privilege-Escalation-Exploit (February 13, 2026)
- Exploit #12031 - CVE-2025-6018 (October 24, 2025)
- Exploit #11881 - PAM-UDisks-PrivEsc-Metasploit (Metasploit modules for the PAM Environment and Udisks PE exploits.) (August 22, 2025)
- Exploit #11761 - PAM-UDisks-PrivEsc-Metasploit (Metasploit modules for the PAM Environment and Udisks PE exploits.) (July 3, 2025)
- Exploit #11750 - CVE-2025-6018-19-exploit () (July 3, 2025)
- Exploit #11655 - CVE-2025-6018: LPE from unprivileged to allow_active in *SUSE 15\'s PAM (June 19, 2025)