Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-4598

21
FAUCET Score

CVE-2025-4598 is a medium-severity vulnerability in systemd-coredump affecting various Linux distributions, including Debian, Oracle, and Red Hat. This flaw allows a local attacker to force a SUID process to crash and, through a race condition, replace it with a non-SUID binary to access the original process's coredump. This can lead to the disclosure of sensitive data, such as /etc/shadow content, loaded by the original SUID process. The attack requires low privileges and high attack complexity, with a CVSS score of 4.7. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness of the issue.

Impacted Technologies

VendorProductVersion(s)CPE
< 252.37CPE matchmatch criteria
cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*
>= 253, < 253.32CPE matchmatch criteria
cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*
>= 254, < 254.25CPE matchmatch criteria
cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*
>= 255, < 255.19CPE matchmatch criteria
cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*
>= 256, < 256.14CPE matchmatch criteria
cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.72%
Probability of exploitation in next 30 days
EPSS Percentile
50.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0072 is in the 89th percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (28)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: azl3 systemd 255-24 on Azure Linux 3.0Fixed in: 255-24
microsoftpatch availablevia msrc
Product: 19661-17086Fixed in: 250.3-23
microsoftpatch availablevia msrc
Product: 20531-17086Fixed in: 250.3-23
microsoftpatch availablevia msrc
Product: 19683-17084
microsoftpatch availablevia msrc
Product: 17087-17086
microsoftpatch availablevia msrc
Product: 20431-17084Fixed in: 255-24
microsoftpatch availablevia msrc
Product: 20576-17084Fixed in: 255-24
microsoftpatch availablevia msrc
Product: cbl2 systemd 250.3-22 on CBL Mariner 2.0Fixed in: 250.3-23
microsoftpatch availablevia msrc
Product: cbl2 systemd 250.3-23 on CBL Mariner 2.0Fixed in: 250.3-23
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.96.2-1 on Azure Linux 3.0
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0
microsoftpatch availablevia msrc
Product: azl3 systemd 255-23 on Azure Linux 3.0Fixed in: 255-24
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: systemd-0:252-55.el9_7.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 8Fixed in: rhceph/rhceph-8-rhel9:sha256:c1c3e3e46bb57c2c99378b7336aa2c2015b7279dcb3df7fdccc8c3dee1522ba6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:d4e8987a100ea60942306f1564679e51fa1364f6124fbfb3100959f83a1f16bf
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-ui-rhel9:sha256:8af6fd7c8fe38d6bfd22e42810badde0aeeae738ea28667ae29dbc0cf4266f3e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Insights proxy 1.5Fixed in: insights-proxy/insights-proxy-container-rhel9:sha256:345d8bc236043df01ce0557357d20fa443719dc943038f9648cfac0c5a465cfe
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 8Fixed in: rhceph/rhceph-8-rhel9:sha256:c95ae228c11ea94b9c111d80df530af10f4a0d9198ccdf03b3685b9413b96fa8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7Fixed in: rhceph/rhceph-7-rhel9:sha256:cfaf2a3c9513bd280265b0e2ca5f7d60022a2e362027becfeb2c133179925523
View patch
redhatvendor investigatingvia nvd_reference
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: systemd
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: systemd
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: systemd
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: rpm-ostree

Vendor Advisories (5)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
redhatCVE-2025-4598Moderate

systemd-coredump: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump

May 29, 2025
microsoft2025-May/CVE-2025-4598

Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump

May 13, 2025

References

cert-portal.siemens.com / productcert/html/ssa-082556.html
blogs.oracle.com / linux/post/analysis-of-cve-2025-4598
ExploitThird Party Advisory
ciq.com / blog/the-real-danger-of-systemd-coredump-cve-2025-4598
ExploitThird Party Advisory
seclists.org / fulldisclosure/2025/Jun/9
lists.debian.org / debian-lts-announce/2025/07/msg00022.html
openwall.com / lists/oss-security/2025/08/18/3
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2025/06/05/1
Mailing List
openwall.com / lists/oss-security/2025/06/05/3
Mailing List
openwall.com / lists/oss-security/2025/08/18/3
access.redhat.com / errata/RHSA-2025:22660
access.redhat.com / errata/RHSA-2025:22868
access.redhat.com / errata/RHSA-2025:23227
access.redhat.com / errata/RHSA-2025:23234
access.redhat.com / errata/RHSA-2026:0414
access.redhat.com / errata/RHSA-2026:1652
access.redhat.com / errata/RHSA-2026:18153
access.redhat.com / security/cve/CVE-2025-4598
Vendor Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
openwall.com / lists/oss-security/2025/05/29/3
Mailing List