CVE-2025-4598

Siemens ProductCERT Advisory SSA-082556

mediumEPSS 0.8%

Description

A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.

Metrics

Severity
medium
no public PoC known
4.7
Source: nvd-v3
55.4 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.8 %
Low — model estimates < 1% exploitation likelihood.
Published
2021-09-26 00:00 UTC
CWE-364

Weakness classes (CWE)

  • CWE-364Base

    Signal Handler Race Condition

    The product uses a signal handler that introduces a race condition.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-31 18:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/4xxx/CVE-2025-4598.json">CVE-2025-4598</a>
    • Reference: https://access.redhat.com/errata/RHSA-2025:22660
    • Reference: https://access.redhat.com/errata/RHSA-2025:22868
    • Reference: https://access.redhat.com/errata/RHSA-2025:23227
  2. CVE Modified2026-08-31 18:17 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://seclists.org/fulldisclosure/2025/Jun/9
    • Reference: http://www.openwall.com/lists/oss-security/2025/06/05/1
    • Reference: http://www.openwall.com/lists/oss-security/2025/06/05/3
    • Reference: http://www.openwall.com/lists/oss-security/2025/08/18/3
  3. CVE Modified2026-08-31 18:17 UTC· 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
    • Reference: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
    • Reference: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
  4. CVE Modified2026-08-21 13:16 UTC· secalert@redhat.com
    • Affected: …, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 (+15)…, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 (+15)
  5. CVE Modified2026-06-30 11:16 UTC· secalert@redhat.com
    • Affected: …, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 (+17)…, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 (+15)

Affected operating systems

  • bsd

    freebsd / freebsd13.2

  • bsd

    freebsd / freebsd13.3

  • bsd

    freebsd / freebsd14.0

  • bsd

    freebsd / freebsd14.1

  • bsd

    netbsd / netbsd

  • linux

    almalinux / almalinux9.0

  • linux

    amazon / amazon_linux2023.0

  • linux

    amazon / amazon_linux

  • linux

    ubuntu / awsbionic

  • linux

    ubuntu / awsjammy

  • linux

    ubuntu / awsnoble

  • linux

    ubuntu / awsresolute

  • linux

    ubuntu / awsxenial

  • linux

    ubuntu / aws-6.8jammy

  • linux

    ubuntu / aws-hwexenial

  • linux

    ubuntu / azurejammy

  • linux

    ubuntu / azurenoble

  • linux

    ubuntu / azureresolute

  • linux

    ubuntu / azurexenial

  • linux

    ubuntu / azure-4.15bionic

  • linux

    suse / basesystem_module15

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux12.0

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • android

    :linux_kernel::0

  • android

    :linux_kernel:Kernel

  • arista

    cloudvision_agni2024.4.0 – 2025.2.2

  • arista

    cloudvision_portal2024.2.0 – 2026.1.0

  • arista

    velocloud_edge4.5.0 – 6.4.1

  • arista

    velocloud_gateway

  • arista

    velocloud_orchestrator

  • bitnami

    java-min1.9.0

  • bitnami

    varnish6.1.0

  • bitnami

    varnish7.4.0

  • Dell

    ECS3.8.1.0-3.8.1.7

  • Dell

    NetWorkervProxy 19.14

  • Dell

    PowerScale OneFSNode Firmware Package 14.1

  • Dell

    Secure Connect GatewayAppliance 5.32.00.18

  • Dell

    Secure Connect Gateway< 5.36.00.16

    fixed in 5.36.00.16

  • Dell

    Secure Connect GatewayAppliance <5.32.00.18

  • gnu

    glibc2.35 – 2.37

  • gnu

    glibc

  • gnupg

    libgcrypt1.11.0 – 1.11.3

  • gnupg

    libgcrypt1.12.0 – 1.12.2

  • gnupg

    libgcrypt1.8.8 – 1.10.4

  • hackage

    xz-clib5.6.3

  • hackage

    xz-clib5.6.4

  • hackage

    xz-clib5.8.0

References & sources

Linked CVEs

Show 291 more CVEs
IDCVE-2025-4598