Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-5791

23
FAUCET Score

CVE-2025-5791 describes a privilege escalation vulnerability in the Rust 'user' crate. This flaw occurs when a user or process is associated with fewer than 1024 groups, causing the system to incorrectly include the root group in the access list. With a CVSS score of 7.1 (HIGH), this vulnerability has a local attack vector, low attack complexity, and can lead to high impact on confidentiality and integrity. There is currently no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage, indicating a low immediate threat.

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat OpenShift Container Platform 4
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Trusted Profile Analyzer
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 10
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat OpenShift Sandboxed Containers 1.1
Range not provided by sourceCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 27th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: 20126-17086Fixed in: 3.2.0.azl2-7
microsoftpatch availablevia msrc
Product: 21397-17084Fixed in: 3.15.0.aks0-14
microsoftpatch availablevia msrc
Product: azl3 kata-containers-cc 3.15.0.aks0-12 on Azure Linux 3.0Fixed in: 3.15.0.aks0-14
microsoftpatch availablevia msrc
Product: cbl2 kata-containers-cc 3.2.0.azl2-7 on CBL Mariner 2.0Fixed in: 3.2.0.azl2-7
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift sandboxed containers 1.1Fixed in: openshift-sandboxed-containers/osc-rhel9-operator:sha256:a6f29da891174e57fcfd131da7aa90c50459ba24164111b83120a1b91f2eabba
View patch
redhatno patchvia redhat_api
Product: Red Hat Trusted Profile AnalyzerFixed in: rhtpa/rhtpa-trustification-service-rhel9
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rust-afterburn
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: rust-ssh-key-dir
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: rust-afterburn

Vendor Advisories (3)

microsoft2025-Jun/CVE-2025-5791

Users: `root` appended to group listings

Jun 10, 2025
rustGHSA-m65q-v92h-cm7qhigh

users may append `root` to group listings

Jun 5, 2025
redhatCVE-2025-5791Important

users: `root` appended to group listings

Jan 15, 2025

References

access.redhat.com / errata/RHSA-2025:12359
access.redhat.com / security/cve/CVE-2025-5791
bugzilla.redhat.com / show_bug.cgi
crates.io / crates/users
github.com / ogham/rust-users/issues/44
rustsec.org / advisories/RUSTSEC-2025-0040.html