Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-6020

27
FAUCET Score

CVE-2025-6020 describes a local privilege escalation vulnerability in the linux-pam module pam_namespace. This flaw allows local users to gain root privileges through symlink attacks and race conditions by exploiting improper handling of user-controlled paths. With a CVSS score of 7.8 (High), this vulnerability has a low attack complexity and requires local access, but can lead to complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat Enterprise Linux 9
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9.0 Update Services For SAP Solutions
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9.2 Update Services For SAP Solutions
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 10
Range not provided by sourceCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.40%
Probability of exploitation in next 30 days
EPSS Percentile
32.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0040 is in the 72nd percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (67)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: cbl2 pam 1.5.1-8 on CBL Mariner 2.0Fixed in: 1.5.1-8
microsoftpatch availablevia msrc
Product: cbl2 pam 1.5.1-7 on CBL Mariner 2.0Fixed in: 1.5.1-8
microsoftpatch availablevia msrc
Product: 19627-17084Fixed in: 1.5.3-5
microsoftpatch availablevia msrc
Product: azl3 pam 1.5.3-5 on Azure Linux 3.0Fixed in: 1.5.3-5
microsoftpatch availablevia msrc
Product: 19580-16823Fixed in: 1.5.1-8
microsoftpatch availablevia msrc
Product: 19916-17086Fixed in: 1.5.1-8
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: pam-0:1.3.1-16.el8_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: pam-0:1.3.1-16.el8_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: pam-0:1.3.1-16.el8_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: pam-0:1.3.1-26.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: pam-0:1.3.1-26.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pam-0:1.5.1-26.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: pam-0:1.5.1-9.el9_0.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: pam-0:1.5.1-15.el9_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: pam-0:1.5.1-24.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Terminal 1.11 on RHEL 9Fixed in: web-terminal/web-terminal-rhel9-operator:1.11-19
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Terminal 1.11 on RHEL 9Fixed in: web-terminal/web-terminal-tooling-rhel9:1.11-8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Terminal 1.12 on RHEL 9Fixed in: web-terminal/web-terminal-tooling-rhel9:1.12-4
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1752066672
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1752065732
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-controller-rhel8:7.13.5-4.1752065732
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1752065737
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1752065731
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-operator-bundle:7.13.5-25
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1752065736
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-rhel8-operator:7.13.5-2.1752065733
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1752065755
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-management-console-rhel8:1.36.0-9
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-operator-bundle:1.36.0-12
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-rhel8-operator:1.36.0-18
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7
View patch
redhatpatch availablevia redhat_api
Product: cert-manager operator for Red Hat OpenShift 1.16Fixed in: cert-manager/jetstack-cert-manager-rhel9:sha256:ec9c6b34a40da29f3ee89b361d94879025a998d34309bf3b63c555f3c225eb16
View patch
redhatpatch availablevia redhat_api
Product: Compliance Operator 1Fixed in: compliance/openshift-compliance-openscap-rhel8:sha256:c953e9f9abf9cf25bf65bb3ffdc86ccf49b3e69a1cf3fbb47b6972e421fd6628
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:bd9cb502def3153c193713b56372694cb555a71b38d4fc0fd9d021bccc5602de
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:c85cfbcaf7888885e57596b7b8bde3894718cfc33326499b24961a66a62cf083
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Insights proxy 1.5Fixed in: insights-proxy/insights-proxy-container-rhel9:sha256:8eb6b896e1eac4080a564e146f95c4166e47ca137083b37119027c6a77011207
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/opentelemetry-collector-rhel8:sha256:93a3f6c10968431079bf0b637b029406d6a0bdc9521f3a02b062af7a3539995e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/opentelemetry-rhel8-operator:sha256:643b9297fe6bf515d142ad8c857d279aa47854aecd0c9cdb90061185ac78987a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/opentelemetry-target-allocator-rhel8:sha256:f49a121a3d0ec81f510680cd47c552f82c48889f28d3f14037c582636085410a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/tempo-gateway-opa-rhel8:sha256:34851d4dd94a887b27d0937a1238d09ac370b4ec06382fe880796dac86c4aa3e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/tempo-gateway-rhel8:sha256:cd011375e307f5cef74d4819f37567f6291259eb1d2795f0cf4b8cb8a90004e0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/tempo-jaeger-query-rhel8:sha256:2a37885dbd9735167854119a546f9ce1b37454a2b57d283fbd8da890c01db767
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/tempo-query-rhel8:sha256:8f2da1e0fc45a36cffbe91f9a1c4449eb0c71671865b7194951ad727c9f7b064
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/tempo-rhel8:sha256:9eaae087bccf2cedfea26d1c0235cfbbe227f9b8f1eda67dc0b33441e319eb85
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.6.0Fixed in: rhosdt/tempo-rhel8-operator:sha256:e0319f6e008b9acca2b111406b25238d1e75ca95b18b09365886a617d2a38882
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift sandboxed containers 1.1Fixed in: openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9:sha256:24722900db1425bf0c27f6ad6f3fb7d79ff9ebc433bdab58423fa71bab76122b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift sandboxed containers 1.1Fixed in: openshift-sandboxed-containers/osc-monitor-rhel9:sha256:9ff002e628e5646b5ab3cc9201087847bea29569b4a1bc135b89d5c1a5f0a422
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift sandboxed containers 1.1Fixed in: openshift-sandboxed-containers/osc-podvm-builder-rhel9:sha256:8f29671308ca658e32e97d5c3b482f7541aae1bca1b71f39b3276a9a334d8108
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift sandboxed containers 1.1Fixed in: openshift-sandboxed-containers/osc-podvm-payload-rhel9:sha256:59fb1f7f1653361d94f7d48b42d8fe19ed3263c1c78654837c11f2135544c1ac
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pam-0:1.5.1-25.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: pam-0:1.6.1-8.el10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10.0 Extended Update SupportFixed in: pam-0:1.6.1-8.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: pam-0:1.1.8-23.el7_9.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pam-0:1.3.1-37.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pam-0:1.3.1-38.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: pam-0:1.3.1-8.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: pam-0:1.3.1-14.el8_4.1
View patch

Vendor Advisories (5)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
redhatCVE-2025-6020Important

linux-pam: Linux-pam directory Traversal

Jun 17, 2025
microsoft2025-Jun/CVE-2025-6020Important

Linux-pam: linux-pam directory traversal

Jun 10, 2025

References

cert-portal.siemens.com / productcert/html/ssa-577017.html
lists.debian.org / debian-lts-announce/2025/09/msg00021.html
openwall.com / lists/oss-security/2025/06/17/1
access.redhat.com / errata/RHSA-2025:10024
access.redhat.com / errata/RHSA-2025:10027
access.redhat.com / errata/RHSA-2025:10180
access.redhat.com / errata/RHSA-2025:10354
access.redhat.com / errata/RHSA-2025:10357
access.redhat.com / errata/RHSA-2025:10358
access.redhat.com / errata/RHSA-2025:10359
access.redhat.com / errata/RHSA-2025:10361
access.redhat.com / errata/RHSA-2025:10362
access.redhat.com / errata/RHSA-2025:10735
access.redhat.com / errata/RHSA-2025:10823
access.redhat.com / errata/RHSA-2025:11386
access.redhat.com / errata/RHSA-2025:11487
access.redhat.com / errata/RHSA-2025:14557
access.redhat.com / errata/RHSA-2025:15099
access.redhat.com / errata/RHSA-2025:15709
access.redhat.com / errata/RHSA-2025:15827
access.redhat.com / errata/RHSA-2025:15828
access.redhat.com / errata/RHSA-2025:16524
access.redhat.com / errata/RHSA-2025:17181
access.redhat.com / errata/RHSA-2025:18219
access.redhat.com / errata/RHSA-2025:20181
access.redhat.com / errata/RHSA-2025:21885
access.redhat.com / errata/RHSA-2025:22019
access.redhat.com / errata/RHSA-2025:9526
access.redhat.com / errata/RHSA-2026:0934
access.redhat.com / security/cve/CVE-2025-6020
bugzilla.redhat.com / show_bug.cgi
github.com / linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx