Improper access control in linux-pam - CVE-2025-6020
Published: June 19, 2025 / Updated: July 3, 2025
Vulnerability identifier: #VU111389
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-6020
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper access restrictions within the pam_namespace module when handling user-controlled paths. A local user can use specially crafted symlinks and race conditions to execute arbitrary code as root.
Affected software
linux-pam
Netezza Appliance
Guardium Data Security Center (GDSC)
DataStage on Cloud Pak for Data
IBM Security Verify Directory
Robotic Process Automation for Cloud Pak
Gentoo Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Development Tools Module
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Fedora
IBM Observability with Instana
Netcool Operations Insight
IBM Power Hardware Management Console (HMC)
OpenShift Compliance Operator
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
IBM MQ Operator
Red Hat Advanced Cluster Security for Kubernetes
IBM TXSeries for Multiplatforms
IBM Edge Application Manager
Red Hat OpenShift Container Platform
LANTIME Operating System Firmware (LTOS)
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
pam-devel
pam
pam (Red Hat package)
pam-extra
pam-debugsource
pam-32bit-debuginfo
pam-32bit
pam-extra-32bit-debuginfo
pam-devel-32bit
pam-extra-32bit
pam-doc
pam-extra-debuginfo
pam-debuginfo
pam (Ubuntu package)
pam-help
pam-libs
sys-libs/pam
IBM API Connect
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Virtualization
Red Hat Ceph Storage
AMQ Broker
IBM CICS TX Advanced
IBM CICS TX Standard
Netezza Appliance
Guardium Data Security Center (GDSC)
DataStage on Cloud Pak for Data
IBM Security Verify Directory
Robotic Process Automation for Cloud Pak
Gentoo Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Development Tools Module
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Fedora
IBM Observability with Instana
Netcool Operations Insight
IBM Power Hardware Management Console (HMC)
OpenShift Compliance Operator
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
IBM MQ Operator
Red Hat Advanced Cluster Security for Kubernetes
IBM TXSeries for Multiplatforms
IBM Edge Application Manager
Red Hat OpenShift Container Platform
LANTIME Operating System Firmware (LTOS)
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
pam-devel
pam
pam (Red Hat package)
pam-extra
pam-debugsource
pam-32bit-debuginfo
pam-32bit
pam-extra-32bit-debuginfo
pam-devel-32bit
pam-extra-32bit
pam-doc
pam-extra-debuginfo
pam-debuginfo
pam (Ubuntu package)
pam-help
pam-libs
sys-libs/pam
IBM API Connect
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Virtualization
Red Hat Ceph Storage
AMQ Broker
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2025-6020
Install updates from vendor's website.
linux-pam - update to 1.7.1
Netezza Appliance - update to 1.0.0.1
IBM Observability with Instana - addressed in versions 1.0.299, 1.0.309
Netcool Operations Insight - update to 1.6.15
Guardium Data Security Center (GDSC) - update to 3.8.5
DataStage on Cloud Pak for Data - update to 5.2.1
LANTIME Operating System Firmware (LTOS) - update to 7.08.025
IBM Qradar SIEM - update to 7.5.0 Update Pack 13
IBM Security Verify Directory - update to 10.0.4.0.1
IBM API Connect - update to 10.0.8.5
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP2, 11.1.1110.0
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.4, 30.0.0
Red Hat OpenShift Serverless - update to 1
pam-devel - addressed in versions 1.1.8-23, 1.3.1-37, 1.3.1-38, 1.5.3-3
pam - addressed in versions 1.1.8-23, 1.3.1-37, 1.3.1-38, 1.5.3-3
pam (Red Hat package) - addressed in versions 1.1.8-23.el7_9.1, 1.3.1-8.el8_2.1, 1.3.1-8.el8_2.2, 1.3.1-14.el8_4.1, 1.3.1-16.el8_6.2, 1.3.1-26.el8_8.1, 1.3.1-37.el8_10, 1.5.1-9.el9_0.2, 1.5.1-9.el9_0.3, 1.5.1-15.el9_2.1, 1.5.1-24.el9_4, 1.5.1-24.el9_4.1, 1.5.1-25.el9_6, 1.5.1-26.el9_6, 1.6.1-8.el10_0
pam - update to 1.3.0-150000.6.83.1
pam-extra - update to 1.3.0-150000.6.83.1
pam-debugsource - update to 1.3.0-150000.6.83.1
pam-devel - update to 1.3.0-150000.6.83.1
pam-32bit-debuginfo - update to 1.3.0-150000.6.83.1
pam-32bit - update to 1.3.0-150000.6.83.1
pam-extra-32bit-debuginfo - update to 1.3.0-150000.6.83.1
pam-devel-32bit - update to 1.3.0-150000.6.83.1
pam-extra-32bit - update to 1.3.0-150000.6.83.1
pam-doc - update to 1.3.0-150000.6.83.1
pam-extra-debuginfo - update to 1.3.0-150000.6.83.1
pam-debuginfo - update to 1.3.0-150000.6.83.1
pam (Ubuntu package) - addressed in versions 1.4.0-11ubuntu2.6, 1.5.3-5ubuntu5.4, 1.5.3-7ubuntu2.3, 1.5.3-7ubuntu4.3
pam - addressed in versions 1.4.0-16, 1.5.2-13, 1.5.3-9
pam-help - addressed in versions 1.4.0-16, 1.5.2-13, 1.5.3-9
pam-devel - addressed in versions 1.4.0-16, 1.5.2-13, 1.5.3-9
pam-debugsource - addressed in versions 1.4.0-16, 1.5.2-13, 1.5.3-9
pam-debuginfo - addressed in versions 1.4.0-16, 1.5.2-13, 1.5.3-9
pam-libs - update to 1.5.3-3
pam-doc - update to 1.5.3-3
pam - update to 1.7.0-6.fc42
sys-libs/pam - update to 1.7.1
OpenShift Compliance Operator - update to 1.8.0
Ansible Automation Platform - addressed in versions 2.4, 2.5
Multicluster Engine for Kubernetes - addressed in versions 2.6.8, 2.7.6, 2.8.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.12.5, 2.13.4
IBM MQ Operator - addressed in versions 3.2.16, 3.6.3, 9.4.3.1-r2
Red Hat Advanced Cluster Security for Kubernetes - update to 4.7.5
OpenShift Virtualization - update to 4.12.20
Red Hat OpenShift Container Platform - addressed in versions 4.12.79, 4.14.54, 4.14.55, 4.15.56, 4.16.44, 4.16.45, 4.18.20, 4.19.4
Red Hat Ceph Storage - update to 7.1
AMQ Broker - update to 7.13.2
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix9
IBM CICS TX Advanced - update to 11.1.0.0 ifix33
IBM CICS TX Standard - update to 11.1.0.0 ifix34
Netezza Appliance - update to 1.0.0.1
IBM Observability with Instana - addressed in versions 1.0.299, 1.0.309
Netcool Operations Insight - update to 1.6.15
Guardium Data Security Center (GDSC) - update to 3.8.5
DataStage on Cloud Pak for Data - update to 5.2.1
LANTIME Operating System Firmware (LTOS) - update to 7.08.025
IBM Qradar SIEM - update to 7.5.0 Update Pack 13
IBM Security Verify Directory - update to 10.0.4.0.1
IBM API Connect - update to 10.0.8.5
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP2, 11.1.1110.0
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.4, 30.0.0
Red Hat OpenShift Serverless - update to 1
pam-devel - addressed in versions 1.1.8-23, 1.3.1-37, 1.3.1-38, 1.5.3-3
pam - addressed in versions 1.1.8-23, 1.3.1-37, 1.3.1-38, 1.5.3-3
pam (Red Hat package) - addressed in versions 1.1.8-23.el7_9.1, 1.3.1-8.el8_2.1, 1.3.1-8.el8_2.2, 1.3.1-14.el8_4.1, 1.3.1-16.el8_6.2, 1.3.1-26.el8_8.1, 1.3.1-37.el8_10, 1.5.1-9.el9_0.2, 1.5.1-9.el9_0.3, 1.5.1-15.el9_2.1, 1.5.1-24.el9_4, 1.5.1-24.el9_4.1, 1.5.1-25.el9_6, 1.5.1-26.el9_6, 1.6.1-8.el10_0
pam - update to 1.3.0-150000.6.83.1
pam-extra - update to 1.3.0-150000.6.83.1
pam-debugsource - update to 1.3.0-150000.6.83.1
pam-devel - update to 1.3.0-150000.6.83.1
pam-32bit-debuginfo - update to 1.3.0-150000.6.83.1
pam-32bit - update to 1.3.0-150000.6.83.1
pam-extra-32bit-debuginfo - update to 1.3.0-150000.6.83.1
pam-devel-32bit - update to 1.3.0-150000.6.83.1
pam-extra-32bit - update to 1.3.0-150000.6.83.1
pam-doc - update to 1.3.0-150000.6.83.1
pam-extra-debuginfo - update to 1.3.0-150000.6.83.1
pam-debuginfo - update to 1.3.0-150000.6.83.1
pam (Ubuntu package) - addressed in versions 1.4.0-11ubuntu2.6, 1.5.3-5ubuntu5.4, 1.5.3-7ubuntu2.3, 1.5.3-7ubuntu4.3
pam - addressed in versions 1.4.0-16, 1.5.2-13, 1.5.3-9
pam-help - addressed in versions 1.4.0-16, 1.5.2-13, 1.5.3-9
pam-devel - addressed in versions 1.4.0-16, 1.5.2-13, 1.5.3-9
pam-debugsource - addressed in versions 1.4.0-16, 1.5.2-13, 1.5.3-9
pam-debuginfo - addressed in versions 1.4.0-16, 1.5.2-13, 1.5.3-9
pam-libs - update to 1.5.3-3
pam-doc - update to 1.5.3-3
pam - update to 1.7.0-6.fc42
sys-libs/pam - update to 1.7.1
OpenShift Compliance Operator - update to 1.8.0
Ansible Automation Platform - addressed in versions 2.4, 2.5
Multicluster Engine for Kubernetes - addressed in versions 2.6.8, 2.7.6, 2.8.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.12.5, 2.13.4
IBM MQ Operator - addressed in versions 3.2.16, 3.6.3, 9.4.3.1-r2
Red Hat Advanced Cluster Security for Kubernetes - update to 4.7.5
OpenShift Virtualization - update to 4.12.20
Red Hat OpenShift Container Platform - addressed in versions 4.12.79, 4.14.54, 4.14.55, 4.15.56, 4.16.44, 4.16.45, 4.18.20, 4.19.4
Red Hat Ceph Storage - update to 7.1
AMQ Broker - update to 7.13.2
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix9
IBM CICS TX Advanced - update to 11.1.0.0 ifix33
IBM CICS TX Standard - update to 11.1.0.0 ifix34
External References
Related Security Bulletins
- Privilege escalation in linux-pam
- Ubuntu update for pam
- Fedora 42 update for pam
- SUSE update for pam
- Red Hat Enterprise Linux 9 update for pam
- Red Hat Enterprise Linux 9 update for pam
- Red Hat Enterprise Linux 8 update for pam
- Red Hat Enterprise Linux 9 update for pam
- Anolis OS update for pam
- openEuler 24.03 LTS SP1 update for pam
- openEuler 24.03 LTS update for pam
- openEuler 22.03 LTS SP4 update for pam
- openEuler 22.03 LTS SP3 update for pam
- Red Hat Enterprise Linux 9 update for pam
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for pam
- Red Hat Enterprise Linux 8 update for pam
- Red Hat Enterprise Linux 8 update for pam
- Red Hat Enterprise Linux 8 update for pam
- Red Hat Enterprise Linux 8 update for pam
- openEuler 20.03 LTS SP4 update for pam
- openEuler 24.03 LTS SP2 update for pam
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.7
- Multiple vulnerabilities in IBM Observability with Instana (Agent)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Gentoo update for PAM
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Security Verify Directory
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM TXSeries for Multiplatforms
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Anolis OS update for pam
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Red Hat Enterprise Linux 9 update for pam
- Red Hat Enterprise Linux 9 update for pam
- Red Hat Enterprise Linux 9 update for pam
- Red Hat Enterprise Linux 8 update for pam
- IBM DataStage on Cloud Pak for Data update for linux-pam
- IBM Power Hardware Management Console (HMC) update for linux-pam
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.8
- Multiple vulnerabilities in AMQ Broker 7.13
- Multiple vulnerabilities in IBM Edge Application Manager
- Anolis OS update for pam
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.13
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Anolis OS update for pam
- Multiple vulnerabilities in OpenShift Compliance Operator
- Multiple vulnerabilities in Netcool Operations Insight
- Red Hat Enterprise Linux 10 update for pam
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Netezza Appliance
- Anolis OS update for pam
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages