CVE-2025-8941: Linux-pam: incomplete fix for cve-2025-6020
A flaw was found in linux-pam. The pamnamespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
Other sources
CVE-2025-8941 – this is the “complete” fix for CVE-2025-6020, a directory-traversal privilege escalation in Linux-PAM’s pamnamespace module. The upstream patch fully addresses the symlink and race-condition attack vectors that were previously mitigated only partially.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8941?
CVE-2025-8941 is considered a critical vulnerability due to its potential to allow local users to elevate privileges to root.
How do I fix CVE-2025-8941?
To fix CVE-2025-8941, you should update the linux-pam package to the latest version provided by your distribution.
Who is affected by CVE-2025-8941?
CVE-2025-8941 affects systems using the linux-pam package, particularly those running vulnerable versions on Red Hat.
What types of attacks can CVE-2025-8941 lead to?
CVE-2025-8941 can lead to privilege escalation attacks through symlink exploits and race conditions.
Is CVE-2025-8941 a complete fix for any previous vulnerabilities?
Yes, CVE-2025-8941 provides a complete fix for CVE-2025-6020.