Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-1390

21
FAUCET Score

CVE-2025-1390 describes a local privilege escalation vulnerability in the pam_cap.so PAM module of libcap. This flaw arises from incorrect parsing of group names in /etc/security/capability.conf, allowing non-intended users to inherit capabilities. With a CVSS score of 6.1 (Medium), an attacker with local user privileges can exploit this by crafting specific usernames to gain elevated capabilities, leading to high integrity impact but no confidentiality or availability impact. There is currently no public exploit code available, it is not listed on the KEV catalog, and community discussion and media coverage are minimal, indicating low current exploitation activity.

Impacted Technologies

VendorProductVersion(s)CPE
OpenAnolisAnolis OS
2.73;0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 32nd percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

codesyspatch availablevia llm_extracted
View patch
esphomepatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 20234-17084Fixed in: 2.69-2
microsoftpatch availablevia msrc
Product: 19275-17084Fixed in: 2.69-2
microsoftpatch availablevia msrc
Product: cbl2 libcap 2.60-4 on CBL Mariner 2.0Fixed in: 2.60-3
microsoftpatch availablevia msrc
Product: cbl2 libcap 2.60-3 on CBL Mariner 2.0Fixed in: 2.60-3
microsoftpatch availablevia msrc
Product: azl3 libcap 2.69-4 on Azure Linux 3.0Fixed in: 2.69-2
microsoftpatch availablevia msrc
Product: 20232-17086Fixed in: 2.60-3
microsoftpatch availablevia msrc
Product: azl3 libcap 2.69-2 on Azure Linux 3.0Fixed in: 2.69-2
microsoftpatch availablevia msrc
Product: 19274-16823Fixed in: 2.60-3

Vendor Advisories (4)

codesysllm-codesys-fe85e88fbae25bb9CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
esphomellm-esphome-ed450ce9fd6a7380CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
redhatCVE-2025-1390Moderate

libcap: pam_cap: Fix potential configuration parsing error

Feb 18, 2025
microsoft2025-Feb/CVE-2025-1390Moderate

pam_cap: Fix potential configuration parsing error

Feb 11, 2025

References

bugzilla.openanolis.cn / show_bug.cgi