CVE-2025-5791 describes a privilege escalation vulnerability in the Rust 'user' crate. This flaw occurs when a user or process is associated with fewer than 1024 groups, causing the system to incorrectly include the root group in the access list. With a CVSS score of 7.1 (HIGH), this vulnerability has a local attack vector, low attack complexity, and can lead to high impact on confidentiality and integrity. There is currently no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage, indicating a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Trusted Profile Analyzer | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 10 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat OpenShift Sandboxed Containers 1.1 | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.