Linux-pam: incomplete fix for cve-2025-6020
Published Aug 13, 2025
7.8
HIGHCVSS 3.1
EPSS 0.27%
Description
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
Affected products
No data.
No data.
No data.
OpenShift Compliance Operator 1
compliance/openshift-compliance-openscap-rhel8:1.8.0
Fixed · RHSA-2025:21885
RHOSS-1.36-RHEL-8
openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11
Fixed · RHSA-2026:0934
RHOSS-1.36-RHEL-8
openshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11
Fixed · RHSA-2026:0934
RHOSS-1.36-RHEL-8
openshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11
Fixed · RHSA-2026:0934
RHOSS-1.36-RHEL-8
openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10
Fixed · RHSA-2026:0934
RHOSS-1.36-RHEL-8
openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10
Fixed · RHSA-2026:0934
RHOSS-1.36-RHEL-8
openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4
Fixed · RHSA-2026:0934
RHOSS-1.36-RHEL-8
openshift-serverless-1/logic-management-console-rhel8:1.36.0-9
Fixed · RHSA-2026:0934
RHOSS-1.36-RHEL-8
openshift-serverless-1/logic-operator-bundle:1.36.0-12
Fixed · RHSA-2026:0934
RHOSS-1.36-RHEL-8
openshift-serverless-1/logic-rhel8-operator:1.36.0-18
Fixed · RHSA-2026:0934
RHOSS-1.36-RHEL-8
openshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11
Fixed · RHSA-2026:0934
RHOSS-1.36-RHEL-8
openshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7
Fixed · RHSA-2026:0934
Red Hat Discovery 2
discovery/discovery-server-rhel9:2.2.1-1758555934
Fixed · RHSA-2025:16524
Red Hat Enterprise Linux 7 Extended Lifecycle Support
pam-0:1.1.8-23.el7_9.2
Fixed · RHSA-2025:15106
Red Hat Enterprise Linux 8
pam-0:1.3.1-38.el8_10
Fixed · RHSA-2025:14557
Red Hat Enterprise Linux 8.2 Advanced Update Support
pam-0:1.3.1-8.el8_2.2
Fixed · RHSA-2025:15107
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
pam-0:1.3.1-14.el8_4.2
Fixed · RHSA-2025:15104
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
pam-0:1.3.1-14.el8_4.2
Fixed · RHSA-2025:15104
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
pam-0:1.3.1-16.el8_6.3
Fixed · RHSA-2025:15105
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
pam-0:1.3.1-16.el8_6.3
Fixed · RHSA-2025:15105
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
pam-0:1.3.1-16.el8_6.3
Fixed · RHSA-2025:15105
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
pam-0:1.3.1-26.el8_8.2
Fixed · RHSA-2025:15103
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
pam-0:1.3.1-26.el8_8.2
Fixed · RHSA-2025:15103
Red Hat Enterprise Linux 9
pam-0:1.5.1-26.el9_6
Fixed · RHSA-2025:15099
Red Hat Enterprise Linux 9
pam-0:1.5.1-26.el9_6
Fixed · RHSA-2025:15099
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
pam-0:1.5.1-9.el9_0.3
Fixed · RHSA-2025:15100
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
pam-0:1.5.1-15.el9_2.2
Fixed · RHSA-2025:15101
Red Hat Enterprise Linux 9.4 Extended Update Support
pam-0:1.5.1-24.el9_4.1
Fixed · RHSA-2025:15102
Red Hat Insights proxy 1.5
insights-proxy/insights-proxy-container-rhel9:1.5.7-1759331989
Fixed · RHSA-2025:17181
Red Hat OpenShift sandboxed containers 1.1
openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9:1.10.2-1757422110
Fixed · RHSA-2025:15709
Red Hat OpenShift sandboxed containers 1.1
openshift-sandboxed-containers/osc-monitor-rhel9:1.10.2-1757421804
Fixed · RHSA-2025:15709
Red Hat OpenShift sandboxed containers 1.1
openshift-sandboxed-containers/osc-podvm-builder-rhel9:1.10.2-1757421879
Fixed · RHSA-2025:15709
Red Hat OpenShift sandboxed containers 1.1
openshift-sandboxed-containers/osc-podvm-payload-rhel9:1.10.2-1757422401
Fixed · RHSA-2025:15709
Red Hat Web Terminal 1.11 on RHEL 9
web-terminal/web-terminal-rhel9-operator:1.11-19
Fixed · RHSA-2025:15828
Red Hat Web Terminal 1.11 on RHEL 9
web-terminal/web-terminal-tooling-rhel9:1.11-8
Fixed · RHSA-2025:15828
Red Hat Web Terminal 1.12 on RHEL 9
web-terminal/web-terminal-tooling-rhel9:1.12-4
Fixed · RHSA-2025:15827
cert-manager operator for Red Hat OpenShift 1.16
cert-manager/jetstack-cert-manager-rhel9:v1.16.5-1760515757
Fixed · RHSA-2025:18219
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Compliance Operator 1 | compliance/openshift-compliance-openscap-rhel8:1.8.0 | Fixed | RHSA-2025:21885 |
| RHOSS-1.36-RHEL-8 | openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11 | Fixed | RHSA-2026:0934 |
| RHOSS-1.36-RHEL-8 | openshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11 | Fixed | RHSA-2026:0934 |
| RHOSS-1.36-RHEL-8 | openshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11 | Fixed | RHSA-2026:0934 |
| RHOSS-1.36-RHEL-8 | openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10 | Fixed | RHSA-2026:0934 |
| RHOSS-1.36-RHEL-8 | openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10 | Fixed | RHSA-2026:0934 |
| RHOSS-1.36-RHEL-8 | openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4 | Fixed | RHSA-2026:0934 |
| RHOSS-1.36-RHEL-8 | openshift-serverless-1/logic-management-console-rhel8:1.36.0-9 | Fixed | RHSA-2026:0934 |
| RHOSS-1.36-RHEL-8 | openshift-serverless-1/logic-operator-bundle:1.36.0-12 | Fixed | RHSA-2026:0934 |
| RHOSS-1.36-RHEL-8 | openshift-serverless-1/logic-rhel8-operator:1.36.0-18 | Fixed | RHSA-2026:0934 |
| RHOSS-1.36-RHEL-8 | openshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11 | Fixed | RHSA-2026:0934 |
| RHOSS-1.36-RHEL-8 | openshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7 | Fixed | RHSA-2026:0934 |
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:2.2.1-1758555934 | Fixed | RHSA-2025:16524 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | pam-0:1.1.8-23.el7_9.2 | Fixed | RHSA-2025:15106 |
| Red Hat Enterprise Linux 8 | pam-0:1.3.1-38.el8_10 | Fixed | RHSA-2025:14557 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | pam-0:1.3.1-8.el8_2.2 | Fixed | RHSA-2025:15107 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | pam-0:1.3.1-14.el8_4.2 | Fixed | RHSA-2025:15104 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | pam-0:1.3.1-14.el8_4.2 | Fixed | RHSA-2025:15104 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | pam-0:1.3.1-16.el8_6.3 | Fixed | RHSA-2025:15105 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | pam-0:1.3.1-16.el8_6.3 | Fixed | RHSA-2025:15105 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | pam-0:1.3.1-16.el8_6.3 | Fixed | RHSA-2025:15105 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | pam-0:1.3.1-26.el8_8.2 | Fixed | RHSA-2025:15103 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | pam-0:1.3.1-26.el8_8.2 | Fixed | RHSA-2025:15103 |
| Red Hat Enterprise Linux 9 | pam-0:1.5.1-26.el9_6 | Fixed | RHSA-2025:15099 |
| Red Hat Enterprise Linux 9 | pam-0:1.5.1-26.el9_6 | Fixed | RHSA-2025:15099 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | pam-0:1.5.1-9.el9_0.3 | Fixed | RHSA-2025:15100 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | pam-0:1.5.1-15.el9_2.2 | Fixed | RHSA-2025:15101 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | pam-0:1.5.1-24.el9_4.1 | Fixed | RHSA-2025:15102 |
| Red Hat Insights proxy 1.5 | insights-proxy/insights-proxy-container-rhel9:1.5.7-1759331989 | Fixed | RHSA-2025:17181 |
| Red Hat OpenShift sandboxed containers 1.1 | openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9:1.10.2-1757422110 | Fixed | RHSA-2025:15709 |
| Red Hat OpenShift sandboxed containers 1.1 | openshift-sandboxed-containers/osc-monitor-rhel9:1.10.2-1757421804 | Fixed | RHSA-2025:15709 |
| Red Hat OpenShift sandboxed containers 1.1 | openshift-sandboxed-containers/osc-podvm-builder-rhel9:1.10.2-1757421879 | Fixed | RHSA-2025:15709 |
| Red Hat OpenShift sandboxed containers 1.1 | openshift-sandboxed-containers/osc-podvm-payload-rhel9:1.10.2-1757422401 | Fixed | RHSA-2025:15709 |
| Red Hat Web Terminal 1.11 on RHEL 9 | web-terminal/web-terminal-rhel9-operator:1.11-19 | Fixed | RHSA-2025:15828 |
| Red Hat Web Terminal 1.11 on RHEL 9 | web-terminal/web-terminal-tooling-rhel9:1.11-8 | Fixed | RHSA-2025:15828 |
| Red Hat Web Terminal 1.12 on RHEL 9 | web-terminal/web-terminal-tooling-rhel9:1.12-4 | Fixed | RHSA-2025:15827 |
| cert-manager operator for Red Hat OpenShift 1.16 | cert-manager/jetstack-cert-manager-rhel9:v1.16.5-1760515757 | Fixed | RHSA-2025:18219 |
No package ranges for this CVE.
Remediation
Vendor solution
Disable the `pam_namespace` module if it is not essential for your environment, or carefully review and configure it to avoid operating on any directories or paths that can be influenced or controlled by unprivileged users, such as user home directories or world-writable locations like `/tmp`.
Red Hat statement
This vulnerability in pam_namespace is rated Important because it allows a local, unprivileged user to escalate privileges to root by exploiting symlink attacks or race conditions in polyinstantiated directories under their control. Successful exploitation requires only the ability to create and manipulate filesystem paths in such directories, without the need for special capabilities or kernel-level vulnerabilities. In multi-user environments—such as shared systems, terminal servers, or certain container deployments, an unprotected or misconfigured pam_namespace configuration can serve as a single point of compromise. Privilege escalation flaws of this nature may also be chained with other vulnerabilities to maintain persistence or evade detection, further increasing the overall impact.
Red Hat mitigation
Disable the `pam_namespace` module if it is not essential for your environment, or carefully review and configure it to avoid operating on any directories or paths that can be influenced or controlled by unprivileged users, such as user home directories or world-writable locations like `/tmp`.
References (21)
- https://access.redhat.com/errata/RHSA-2025:14557 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15099 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15100 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15101 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15102 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15103 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15104 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15105 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15106 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15107 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15709 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15827 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15828 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:16524 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:17181 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:18219 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:21885 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-8941 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2388220 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2025-8941
- https://www.cve.org/CVERecord?id=CVE-2025-8941
Change history (0)
No recorded changes yet.