High [CVE-2025-6020] linux-pam directory traversal
This high-severity Red Hat Linux advisory covers CVE-2025-6020 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.2 Advanced Update Support.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
This vulnerability in pam_namespace marked as Important rather than Moderate due to its direct impact on privilege boundaries and the ease of exploitation in common configurations.
By leveraging symlink attacks or race conditions in polyinstantiated directories under their control, unprivileged local users can escalate to root, compromising the entire system.
Since pam_namespace is often used in multi-user environments (e.g., shared systems, terminal servers, containers), a misconfigured or partially protected setup becomes a single point of failure. The attack does not require special capabilities or kernel-level exploits—just timing and control over certain paths—making it both reliable and low-barrier.
Moreover, privilege escalation flaws like this can be chained with other vulnerabilities to persist or evade detection, further amplifying the risk. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Weakness: CWE-22.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 21 days ago·verify at source
- pam-0:1.6.1-8.el10
- pam-0:1.6.1-8.el10_0
- pam-0:1.1.8-23.el7_9.1
- pam-0:1.3.1-37.el8_10
- pam-0:1.3.1-38.el8_10
- pam-0:1.3.1-8.el8_2.1
- pam-0:1.3.1-14.el8_4.1
- pam-0:1.3.1-16.el8_6.2
- pam-0:1.3.1-26.el8_8.1
- pam-0:1.5.1-26.el9_6
- pam-0:1.5.1-25.el9_6
- pam-0:1.5.1-9.el9_0.2
- pam-0:1.5.1-15.el9_2.1
- pam-0:1.5.1-24.el9_4
- web-terminal/web-terminal-rhel9-operator:1.11-19
- web-terminal/web-terminal-tooling-rhel9:1.11-8
- web-terminal/web-terminal-tooling-rhel9:1.12-4
- rhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1752066672
- rhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1752065732
- rhpam-7/rhpam-controller-rhel8:7.13.5-4.1752065732
- rhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1752065737
- rhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1752065731
- rhpam-7/rhpam-operator-bundle:7.13.5-25
- rhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1752065736
- rhpam-7/rhpam-rhel8-operator:7.13.5-2.1752065733
- rhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1752065755
- openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11
- openshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11
- openshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11
- openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10
- openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10
- openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4
- openshift-serverless-1/logic-management-console-rhel8:1.36.0-9
- openshift-serverless-1/logic-operator-bundle:1.36.0-12
- openshift-serverless-1/logic-rhel8-operator:1.36.0-18
- openshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11
- openshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7
- cert-manager/jetstack-cert-manager-rhel9:v1.16.5-1760515757
- compliance/openshift-compliance-openscap-rhel8:1.8.0
- discovery/discovery-server-rhel9:2.0.0-1752592913
- RHSA-2025:20181
- RHSA-2025:22019
- RHSA-2025:10357
- RHSA-2025:10027
- RHSA-2025:14557
- RHSA-2025:10362
- RHSA-2025:10361
- RHSA-2025:10359
- RHSA-2025:10358
- RHSA-2025:15099
Official advisory · high-confidence parse· fetched 21 days ago·verify at source
Mitigation checklist
- Disable the `pam_namespace` module if it is not essential for your environment, or carefully review and configure it to avoid operating on any directories or paths that can be influenced or controlled by unprivileged users, such as user home directories or world-writable locations like `/tmp`.
Official advisory · high-confidence parse· fetched 21 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.