Link following in linux-pam - CVE-2025-8941

 

Link following in linux-pam - CVE-2025-8941

Published: September 3, 2025


Vulnerability identifier: #VU114769
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-8941
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an insecure link following issue in the pam_namespace module. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.

The vulnerability exists due to incomplete fix for #VU111389 (CVE-2025-6020).


Affected software

linux-pam
Netezza Appliance
Guardium Data Security Center (GDSC)
IBM Observability with Instana
Netcool Operations Insight
OpenShift Compliance Operator
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
IBM MQ Operator
IBM Power Hardware Management Console (HMC)
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
pam-devel
pam
pam (Red Hat package)
IBM API Connect
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Virtualization
AMQ Broker

How to mitigate CVE-2025-8941

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Netezza Appliance - update to 1.0.0.1
IBM Observability with Instana - addressed in versions 1.0.304, 1.0.309
Netcool Operations Insight - update to 1.6.15
Guardium Data Security Center (GDSC) - update to 3.8.5
IBM API Connect - update to 10.0.8.5
Red Hat OpenShift Serverless - update to 1
pam-devel - update to 1.1.8-23
pam - update to 1.1.8-23
pam (Red Hat package) - addressed in versions 1.3.1-8.el8_2.2, 1.5.1-9.el9_0.3, 1.5.1-24.el9_4.1, 1.5.1-26.el9_6
OpenShift Compliance Operator - update to 1.8.0
Ansible Automation Platform - update to 2.4
Multicluster Engine for Kubernetes - addressed in versions 2.7.6, 2.8.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.12.5, 2.13.4
IBM MQ Operator - addressed in versions 3.2.16, 3.6.3, 9.4.3.1-r2
OpenShift Virtualization - update to 4.12.20
AMQ Broker - update to 7.13.2
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP3, 11.1.1110.0

External References

Related Security Bulletins