CVE-2025-15480 affects Ubuntu's desktop-provision package version 24.04.4, where sensitive user credentials including password hashes may be inadvertently exposed during crash reporting. When installation failures occur and users submit bug reports to Launchpad, the vulnerability allows these credentials to be included in attached diagnostic logs, creating a significant confidentiality risk. The vulnerability carries a CVSS score of 9.1 (CRITICAL) with a network-based attack vector requiring no authentication or user interaction, and low attack complexity. The primary impact is a high-severity confidentiality breach affecting user credentials, though system integrity and availability are not compromised. The EPSS score of 0.0005 indicates it is not currently prevalent among actively exploited vulnerabilities, ranking higher than only 0.16% of known CVEs. While the vulnerability is not yet included in the CISA Known Exploited Vulnerabilities catalog, it remains on active monitoring lists due to its critical severity rating and the ease of exploitation. No public exploit code has been widely distributed, but the straightforward nature of the flaw and its presence in active tracking suggests heightened community attention and potential for future exploitation attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
24.04.4CPE matchmatch criteria | cpe:2.3:a:canonical:ubuntu_desktop_provision:24.04.4:*:*:*:*:*:*:* | ||
>= 0, <= 24.04.4CPE match | cpe:2.3:o:canonical:ubuntu:*:*:*:*:*:*:*:* | ||
>= 0, <= 25.04CPE match | cpe:2.3:o:canonical:ubuntu:*:*:*:*:*:*:*:* | ||
>= 0, <= 25.10CPE match | cpe:2.3:o:canonical:ubuntu:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.