CVE-2025-1390

EUVD-2025-4857
The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
libcap
Amazon Linux 2
0:2.54-1.amzn2.0.3
fixed
Amazon Linux 2023
0:2.48-2.amzn2023.0.4
fixed
libcap-debuginfo
Amazon Linux 2
0:2.54-1.amzn2.0.3
fixed
Amazon Linux 2023
0:2.48-2.amzn2023.0.4
fixed
libcap-debugsource
Amazon Linux 2023
0:2.48-2.amzn2023.0.4
fixed
libcap-devel
Amazon Linux 2
0:2.54-1.amzn2.0.3
fixed
Amazon Linux 2023
0:2.48-2.amzn2023.0.4
fixed
libcap-static
Amazon Linux 2
0:2.54-1.amzn2.0.3
fixed
Amazon Linux 2023
0:2.48-2.amzn2023.0.4
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
libcap
Azure Linux 3.0
0:2.69-2.azl3
fixed
CBL-Mariner 2.0
0:2.60-3.cm2
fixed