CVE-2025-1390 describes a local privilege escalation vulnerability in the pam_cap.so PAM module of libcap. This flaw arises from incorrect parsing of group names in /etc/security/capability.conf, allowing non-intended users to inherit capabilities. With a CVSS score of 6.1 (Medium), an attacker with local user privileges can exploit this by crafting specific usernames to gain elevated capabilities, leading to high integrity impact but no confidentiality or availability impact. There is currently no public exploit code available, it is not listed on the KEV catalog, and community discussion and media coverage are minimal, indicating low current exploitation activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| OpenAnolis | Anolis OS | 2.73;0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025libcap: pam_cap: Fix potential configuration parsing error
Feb 18, 2025pam_cap: Fix potential configuration parsing error
Feb 11, 2025