Race condition in Rack - CVE-2025-32441

 

Race condition in Rack - CVE-2025-32441

Published: June 26, 2025


Vulnerability identifier: #VU111976
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-32441
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists because when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session. A remote user can trigger a long running request (within that same session) adjacent to the user logging out, in order to retain illicit access even after a user has attempted to logout.


Affected software

Rack
SUSE Linux Enterprise Server 15 SP5
SUSE Enterprise Server 15 SP3 Business Critical
SUSE Linux Enterprise High Availability Extension 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Ubuntu
Public Cloud Module
Server Applications Module
openSUSE Leap
Fedora
IBM Cloud Pak for Watson AIOps
ruby-rack (Ubuntu package)
ruby2.5-rubygem-rack
ruby2.5-rubygem-rack-doc
ruby2.5-rubygem-rack-testsuite
rubygem-rack
rmt-server-pubcloud
rmt-server-debuginfo
rmt-server-config
rmt-server
rmt-server-debugsource

How to mitigate CVE-2025-32441

Install updates from vendor's website.

Rack - update to 2.2.14
IBM Cloud Pak for Watson AIOps - update to 4.10.0
ruby-rack (Ubuntu package) - addressed in versions 1.5.2-3+deb8u3ubuntu1~esm10, 1.6.4-3ubuntu0.2+esm8, 1.6.4-4ubuntu0.2+esm8, 2.0.7-2ubuntu0.1+esm7, 2.1.4-5ubuntu1.1+esm2, 2.2.7-1ubuntu0.3, 2.2.7-1.1ubuntu0.25.04.1
ruby2.5-rubygem-rack - update to 2.0.8-150000.3.31.1
ruby2.5-rubygem-rack-doc - update to 2.0.8-150000.3.31.1
ruby2.5-rubygem-rack-testsuite - update to 2.0.8-150000.3.31.1
rubygem-rack - addressed in versions 2.2.21-1.fc41, 2.2.21-9.fc42
rmt-server-pubcloud - update to 2.23-150500.3.34.2
rmt-server-debuginfo - update to 2.23-150500.3.34.2
rmt-server-config - update to 2.23-150500.3.34.2
rmt-server - update to 2.23-150500.3.34.2
rmt-server-debugsource - update to 2.23-150500.3.34.2

External References

Related Security Bulletins