CVE-2025-4598

Source
https://cve.org/CVERecord?id=CVE-2025-4598
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4598.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-4598
Downstream
Related
Published
2025-05-30T14:15:23.557Z
Modified
2026-04-16T04:36:23.058510827Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.

A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.

References

Affected packages

Git / github.com/systemd/systemd

Affected ranges

Type
GIT
Repo
https://github.com/systemd/systemd
Events
Introduced
Fixed
Introduced
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "256"
        },
        {
            "fixed": "256.14"
        },
        {
            "introduced": "257"
        },
        {
            "fixed": "257.6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8-NA"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "9-NA"
        }
    ]
}
Type
GIT
Repo
https://github.com/systemd/systemd-stable
Events
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "252.37"
        },
        {
            "introduced": "253"
        },
        {
            "fixed": "253.32"
        },
        {
            "introduced": "254"
        },
        {
            "fixed": "254.25"
        },
        {
            "introduced": "255"
        },
        {
            "fixed": "255.19"
        }
    ]
}

Affected versions

Other
systemd-v1
systemd-v10
systemd-v11
systemd-v12
systemd-v13
systemd-v14
systemd-v15
systemd-v16
systemd-v17
systemd-v18
systemd-v183
systemd-v184
systemd-v185
systemd-v186
systemd-v187
systemd-v188
systemd-v189
systemd-v19
systemd-v190
systemd-v191
systemd-v192
systemd-v193
systemd-v194
systemd-v195
systemd-v196
systemd-v2
systemd-v20
systemd-v21
systemd-v22
systemd-v23
systemd-v24
systemd-v25
systemd-v26
systemd-v27
systemd-v28
systemd-v29
systemd-v3
systemd-v30
systemd-v31
systemd-v32
systemd-v33
systemd-v34
systemd-v35
systemd-v36
systemd-v37
systemd-v38
systemd-v39
systemd-v4
systemd-v40
systemd-v41
systemd-v42
systemd-v43
systemd-v44
systemd-v5
systemd-v6
systemd-v7
systemd-v8
systemd-v9
v1
v10
v11
v12
v13
v14
v15
v16
v17
v18
v183
v184
v185
v186
v187
v188
v189
v19
v190
v191
v192
v193
v194
v195
v196
v197
v198
v199
v2
v20
v200
v201
v202
v203
v204
v205
v206
v207
v208
v209
v21
v210
v211
v212
v213
v214
v215
v216
v217
v218
v219
v22
v220
v221
v222
v223
v224
v225
v226
v227
v228
v229
v23
v230
v231
v232
v233
v234
v235
v236
v237
v238
v239
v24
v240
v241
v241-rc1
v241-rc2
v242
v242-rc1
v242-rc2
v242-rc3
v242-rc4
v243
v243-rc1
v243-rc2
v244
v244-rc1
v245
v245-rc1
v245-rc2
v246
v246-rc1
v246-rc2
v247
v247-rc1
v247-rc2
v248
v248-2
v248-rc1
v248-rc2
v248-rc3
v248-rc4
v249
v249-rc1
v249-rc2
v249-rc3
v25
v250
v250-rc1
v250-rc2
v250-rc3
v251
v251-rc1
v251-rc2
v251-rc3
v252
v252-rc1
v252-rc2
v252-rc3
v253
v254
v255
v256
v257
v26
v27
v28
v29
v3
v30
v31
v32
v33
v34
v35
v36
v37
v38
v39
v4
v40
v41
v42
v43
v44
v5
v6
v7
v8
v9
v252.*
v252.1
v252.10
v252.11
v252.12
v252.13
v252.14
v252.15
v252.16
v252.17
v252.18
v252.19
v252.2
v252.20
v252.21
v252.22
v252.23
v252.24
v252.25
v252.26
v252.27
v252.28
v252.29
v252.3
v252.30
v252.31
v252.32
v252.33
v252.34
v252.35
v252.36
v252.4
v252.5
v252.6
v252.7
v252.8
v252.9
v253.*
v253.1
v253.10
v253.11
v253.12
v253.13
v253.14
v253.15
v253.16
v253.17
v253.18
v253.19
v253.2
v253.20
v253.21
v253.23
v253.24
v253.25
v253.26
v253.27
v253.28
v253.29
v253.3
v253.30
v253.31
v253.4
v253.5
v253.6
v253.7
v253.8
v253.9
v254.*
v254.1
v254.10
v254.11
v254.12
v254.13
v254.14
v254.15
v254.16
v254.17
v254.18
v254.19
v254.2
v254.20
v254.21
v254.22
v254.23
v254.24
v254.3
v254.4
v254.5
v254.6
v254.7
v254.8
v254.9
v255.*
v255.1
v255.10
v255.11
v255.12
v255.13
v255.14
v255.15
v255.16
v255.17
v255.18
v255.2
v255.3
v255.4
v255.5
v255.6
v255.7
v255.8
v255.9
v256.*
v256.1
v256.10
v256.11
v256.12
v256.13
v256.2
v256.3
v256.4
v256.5
v256.6
v256.7
v256.8
v256.9
v257.*
v257.1
v257.2
v257.3
v257.4
v257.5

Database specific

vanir_signatures_modified
"2026-04-12T15:59:37Z"
vanir_signatures
[
    {
        "id": "CVE-2025-4598-4d971043",
        "signature_version": "v1",
        "signature_type": "Function",
        "source": "https://github.com/systemd/systemd-stable/commit/7c9b17c9343e143465b6649d021a68a8c16b9a6e",
        "deprecated": false,
        "target": {
            "function": "save_context",
            "file": "src/coredump/coredump.c"
        },
        "digest": {
            "function_hash": "16046565717551197252257395198478956374",
            "length": 1538.0
        }
    },
    {
        "id": "CVE-2025-4598-4ec6ba05",
        "signature_version": "v1",
        "digest": {
            "function_hash": "16046565717551197252257395198478956374",
            "length": 1538.0
        },
        "source": "https://github.com/systemd/systemd-stable/commit/e507f508a7e9096dbf8bde689e3eb43f3be4c91b",
        "deprecated": false,
        "target": {
            "function": "save_context",
            "file": "src/coredump/coredump.c"
        },
        "signature_type": "Function"
    },
    {
        "id": "CVE-2025-4598-7a2bd108",
        "signature_version": "v1",
        "signature_type": "Function",
        "source": "https://github.com/systemd/systemd-stable/commit/8f21d057e4a216cd60340660e4e9c8f32aab6e00",
        "deprecated": false,
        "target": {
            "function": "save_context",
            "file": "src/coredump/coredump.c"
        },
        "digest": {
            "function_hash": "16046565717551197252257395198478956374",
            "length": 1538.0
        }
    },
    {
        "id": "CVE-2025-4598-7f6d6ca7",
        "signature_version": "v1",
        "signature_type": "Function",
        "source": "https://github.com/systemd/systemd-stable/commit/32c4237a2bc8a29ceefbc277356e72e36889bedd",
        "deprecated": false,
        "target": {
            "function": "save_context",
            "file": "src/coredump/coredump.c"
        },
        "digest": {
            "function_hash": "86472870267374900837527740744553737822",
            "length": 1898.0
        }
    },
    {
        "id": "CVE-2025-4598-82f13eb6",
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/systemd/systemd-stable/commit/8f21d057e4a216cd60340660e4e9c8f32aab6e00",
        "deprecated": false,
        "target": {
            "file": "src/coredump/coredump.c"
        },
        "digest": {
            "line_hashes": [
                "220796398704393213725680744786784732470",
                "49074709061547304596575206381315648943",
                "229800555317423346505805691286205146148",
                "299788836959299593314243482012844247994"
            ],
            "threshold": 0.9
        }
    },
    {
        "id": "CVE-2025-4598-9f1ee238",
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/systemd/systemd-stable/commit/e507f508a7e9096dbf8bde689e3eb43f3be4c91b",
        "deprecated": false,
        "target": {
            "file": "src/coredump/coredump.c"
        },
        "digest": {
            "line_hashes": [
                "220796398704393213725680744786784732470",
                "49074709061547304596575206381315648943",
                "229800555317423346505805691286205146148",
                "299788836959299593314243482012844247994"
            ],
            "threshold": 0.9
        }
    },
    {
        "id": "CVE-2025-4598-a01e1f0e",
        "signature_version": "v1",
        "deprecated": false,
        "source": "https://github.com/systemd/systemd-stable/commit/32c4237a2bc8a29ceefbc277356e72e36889bedd",
        "digest": {
            "line_hashes": [
                "220796398704393213725680744786784732470",
                "49074709061547304596575206381315648943",
                "229800555317423346505805691286205146148",
                "299788836959299593314243482012844247994"
            ],
            "threshold": 0.9
        },
        "target": {
            "file": "src/coredump/coredump.c"
        },
        "signature_type": "Line"
    },
    {
        "id": "CVE-2025-4598-b1a1fdc5",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "220796398704393213725680744786784732470",
                "49074709061547304596575206381315648943",
                "229800555317423346505805691286205146148",
                "299788836959299593314243482012844247994"
            ],
            "threshold": 0.9
        },
        "source": "https://github.com/systemd/systemd-stable/commit/7c9b17c9343e143465b6649d021a68a8c16b9a6e",
        "signature_type": "Line",
        "target": {
            "file": "src/coredump/coredump.c"
        },
        "deprecated": false
    }
]
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "4.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "7.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "8.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "10.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "11.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "12.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "6.16"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4598.json"