CVE-2025-4598 is a medium-severity vulnerability in systemd-coredump affecting various Linux distributions, including Debian, Oracle, and Red Hat. This flaw allows a local attacker to force a SUID process to crash and, through a race condition, replace it with a non-SUID binary to access the original process's coredump. This can lead to the disclosure of sensitive data, such as /etc/shadow content, loaded by the original SUID process. The attack requires low privileges and high attack complexity, with a CVSS score of 4.7. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 252.37CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* | ||
>= 253, < 253.32CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* | ||
>= 254, < 254.25CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* | ||
>= 255, < 255.19CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* | ||
>= 256, < 256.14CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025systemd-coredump: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump
May 29, 2025Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump
May 13, 2025