Race Condition in Canonical Apport
Published May 30, 2025
4.7
MEDIUMCVSS 3.1
EPSS 0.74%
Description
Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces.
When handling a crash, the function `_check_global_pid_and_forward`, which detects if the crashing process resided in a container, was being called before `consistency_checks`, which attempts to detect if the crashing process had been replaced. Because of this, if a process crashed and was quickly replaced with a containerized one, apport could be made to forward the core dump to the container, potentially leaking sensitive information. `consistency_checks` is now being called before `_check_global_pid_and_forward`. Additionally, given that the PID-reuse race condition cannot be reliably detected from userspace alone, crashes are only forwarded to containers if the kernel provided a pidfd, or if the crashing process was unprivileged (i.e., if dump mode == 1).
Affected products
-
- Version 2.20StatusaffectedConstraints<=2.32.0
- Version 2.20.1StatusaffectedConstraints<2.20.1-0ubuntu2.30+esm5
- Version 2.20.11StatusaffectedConstraints<2.20.11-0ubuntu27.28
- Version 2.20.11StatusaffectedConstraints<2.20.11-0ubuntu82.7
- Version 2.20.9StatusaffectedConstraints<2.20.9-0ubuntu7.29+esm1
- Version 2.28.1StatusaffectedConstraints<2.28.1-0ubuntu3.6
- Version 2.30.0StatusaffectedConstraints<2.30.0-0ubuntu4.3
- Version 2.32.0StatusaffectedConstraints<2.32.0-0ubuntu5.1
- Version 2.32.0StatusaffectedConstraints<2.33.0-0ubuntu1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Canonical | Apport | unaffected |
|
Configuration 2
- 16.04
- 18.04
- 20.04
- 22.04
- 24.04
- 24.10
- 25.04
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 30, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.74% (0.00745) | 53.09th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.32% (0.00319) | 23.42th | v5 (v2026.06.15) |
| May 31, 2025 | 0.01% (0.00010) | 0.78th | v4 (v2025.03.14) |
References (4)
- http://seclists.org/fulldisclosure/2025/Jun/9
- https://ubuntu.com/security/CVE-2025-5054 vdb-entryThird Party Advisory
- https://ubuntu.com/security/notices/USN-7545-1 vendor-advisoryThird Party Advisory
- https://www.qualys.com/2025/05/29/apport-coredump/apport-coredump.txt third-party-advisoryExploitMitigationThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/fulldisclosure/2025/Jun/9 | ||
| https://ubuntu.com/security/CVE-2025-5054 | vdb-entryThird Party Advisory | |
| https://ubuntu.com/security/notices/USN-7545-1 | vendor-advisoryThird Party Advisory | |
| https://www.qualys.com/2025/05/29/apport-coredump/apport-coredump.txt | third-party-advisoryExploitMitigationThird Party Advisory |
Change history (0)
No recorded changes yet.