#VU114769 Link following in linux-pam - CVE-2025-8941
Published: September 3, 2025
linux-pam
git.kernel.org
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in the pam_namespace module. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
The vulnerability exists due to incomplete fix for #VU111389 (CVE-2025-6020).