Link following in linux-pam - CVE-2025-8941
Published: September 3, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in the pam_namespace module. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
The vulnerability exists due to incomplete fix for #VU111389 (CVE-2025-6020).
Affected software
Netezza Appliance
Guardium Data Security Center (GDSC)
IBM Observability with Instana
Netcool Operations Insight
OpenShift Compliance Operator
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
IBM MQ Operator
IBM Power Hardware Management Console (HMC)
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
pam-devel
pam
pam (Red Hat package)
IBM API Connect
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Virtualization
AMQ Broker
How to mitigate CVE-2025-8941
IBM Observability with Instana - addressed in versions 1.0.304, 1.0.309
Netcool Operations Insight - update to 1.6.15
Guardium Data Security Center (GDSC) - update to 3.8.5
IBM API Connect - update to 10.0.8.5
Red Hat OpenShift Serverless - update to 1
pam-devel - update to 1.1.8-23
pam - update to 1.1.8-23
pam (Red Hat package) - addressed in versions 1.3.1-8.el8_2.2, 1.5.1-9.el9_0.3, 1.5.1-24.el9_4.1, 1.5.1-26.el9_6
OpenShift Compliance Operator - update to 1.8.0
Ansible Automation Platform - update to 2.4
Multicluster Engine for Kubernetes - addressed in versions 2.7.6, 2.8.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.12.5, 2.13.4
IBM MQ Operator - addressed in versions 3.2.16, 3.6.3, 9.4.3.1-r2
OpenShift Virtualization - update to 4.12.20
AMQ Broker - update to 7.13.2
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP3, 11.1.1110.0
External References
Related Security Bulletins
- Privilege escalation in linux-pam
- Red Hat Enterprise Linux 9 update for pam
- Red Hat Enterprise Linux 9 update for pam
- Red Hat Enterprise Linux 9 update for pam
- Red Hat Enterprise Linux 8 update for pam
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.8
- Multiple vulnerabilities in AMQ Broker 7.13
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.13
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- IBM Power HMC update for linux-pam
- Multiple vulnerabilities in OpenShift Compliance Operator
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Netezza Appliance
- Anolis OS update for pam
- Multiple vulnerabilities in Red Hat OpenShift Serverless