Linux Password Hash Theft Flaw – Ubuntu, RHEL, Fedora
- Security researchers have identified two information disclosure flaws affecting several linux distributions, including Ubuntu, Red Hat enterprise Linux, and Fedora.
- tracked as CVE-2025-5054 and CVE-2025-4598, these flaws are race condition bugs.
- Saeed Abbasi, a product manager at Qualys TRU, explained the risk: "These race conditions allow a local attacker to exploit a SUID program and gain read access to...
Newsflash: Critical security flaws expose password hashes on Ubuntu, Red Hat, and Fedora systems. Two details disclosure vulnerabilities, CVE-2025-5054 and CVE-2025-4598, threaten Linux users, enabling local attackers to potentially access sensitive data. These race condition bugs in tools like apport and systemd-coredump could lead to the theft of password hashes from the /etc/shadow file, highlighting the risk of security vulnerability exploitation. News Directory 3 reports on how Qualys TRU discovered these Linux flaws. Updates are available for Ubuntu, and security advisories have been issued by other distributions. Action is needed—upgrade now to fix the information disclosure. Discover what’s next for your system’s security.
Linux Systems Face Security Risk: Password Hashes Exposed in Ubuntu, Red Hat
Security researchers have identified two information disclosure flaws affecting several linux distributions, including Ubuntu, Red Hat enterprise Linux, and Fedora. The vulnerabilities, found in apport and systemd-coredump, could allow local attackers to access sensitive information.
tracked as CVE-2025-5054 and CVE-2025-4598, these flaws are race condition bugs. Triumphant exploitation could give attackers access to core dumps, potentially revealing sensitive data. These tools are designed to handle crash reporting and core dumps in Linux systems, but the vulnerabilities create an opportunity for unauthorized access.
Saeed Abbasi, a product manager at Qualys TRU, explained the risk: “These race conditions allow a local attacker to exploit a SUID program and gain read access to the resulting core dump.” Qualys TRU discovered the Linux flaws.
Red Hat rated CVE-2025-4598 as having moderate severity, citing the complexity required to successfully exploit the vulnerability. An attacker would need to win the race condition and possess an unprivileged local account. Qualys has developed proof-of-concept code demonstrating how an attacker could exploit the coredump of a crashed unix_chkpwd process to obtain password hashes from the /etc/shadow file, highlighting the potential for security vulnerability exploitation.
Security advisories have also been issued by Gentoo,Amazon linux,and Debian. Debian systems are not susceptible to CVE-2025-4598 by default unless the systemd-coredump package is manually installed.
Canonical software security engineer Octavio Galland addressed the issue on Canonical’s blog, stating that if an attacker induces a crash in a privileged process and quickly replaces it with another process with the same ID inside a mount and pid namespace, apport will attempt to forward the core dump into the namespace. Galland added that the attacker must have permissions to create user, mount, and pid namespaces with full capabilities to carry out the exploit.
Canonical’s security team has released updates for the apport package for all affected Ubuntu releases. Users are encouraged to upgrade all packages.Ubuntu 16.04 LTS and later have unattended-upgrades enabled by default, which automatically applies new security updates every 24 hours, ensuring that these patches are applied promptly, mitigating the information disclosure risk.
What’s next
Users of affected Linux distributions should apply the available security updates as soon as possible to mitigate the risk of exploitation. Organizations should review their security configurations and ensure that unattended upgrades are enabled where possible.
