---
id: CVE-2025-6020
title: A flaw was found in linux-pam
summary: >-
  A flaw was found in linux-pam. The module pam_namespace may use access
  user-controlled paths without proper protection, allowing local users to
  elevate their privileges to root via multiple symlink attacks and race
  conditions.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: Red Hat
product: linux-pam
affected:
  - linux-pam < 1.7.1
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - pam (all versions)
  - web-terminal/web-terminal-rhel9-operator (all versions)
  - web-terminal/web-terminal-tooling-rhel9 (all versions)
  - web-terminal/web-terminal-tooling-rhel9 (all versions)
  - rhpam-7/rhpam-businesscentral-monitoring-rhel8 (all versions)
  - rhpam-7/rhpam-businesscentral-rhel8 (all versions)
  - rhpam-7/rhpam-controller-rhel8 (all versions)
  - rhpam-7/rhpam-dashbuilder-rhel8 (all versions)
  - rhpam-7/rhpam-kieserver-rhel8 (all versions)
  - rhpam-7/rhpam-operator-bundle (all versions)
  - rhpam-7/rhpam-process-migration-rhel8 (all versions)
  - rhpam-7/rhpam-rhel8-operator (all versions)
  - rhpam-7/rhpam-smartrouter-rhel8 (all versions)
  - openshift-serverless-1/logic-data-index-ephemeral-rhel8 (all versions)
  - openshift-serverless-1/logic-data-index-postgresql-rhel8 (all versions)
  - openshift-serverless-1/logic-db-migrator-tool-rhel8 (all versions)
  - openshift-serverless-1/logic-jobs-service-ephemeral-rhel8 (all versions)
  - openshift-serverless-1/logic-jobs-service-postgresql-rhel8 (all versions)
  - openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8 (all versions)
  - openshift-serverless-1/logic-management-console-rhel8 (all versions)
  - openshift-serverless-1/logic-operator-bundle (all versions)
  - openshift-serverless-1/logic-rhel8-operator (all versions)
  - openshift-serverless-1/logic-swf-builder-rhel8 (all versions)
  - openshift-serverless-1/logic-swf-devmode-rhel8 (all versions)
  - cert-manager/jetstack-cert-manager-rhel9 (all versions)
  - compliance/openshift-compliance-openscap-rhel8 (all versions)
  - discovery/discovery-server-rhel9 (all versions)
  - discovery/discovery-server-rhel9 (all versions)
  - insights-proxy/insights-proxy-container-rhel9 (all versions)
  - rhosdt/opentelemetry-collector-rhel8 (all versions)
  - rhosdt/opentelemetry-rhel8-operator (all versions)
patched:
  - enterprise_linux_server_v_7_els
  - middleware_containers_for_openshift
  - 8base_openshift_serverless_1_36
  - web_terminal_1_11_on_rhel 9
  - web_terminal_1_12_on_rhel 9
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_e4s_v_9_0
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_eus_v_9_4
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_eus_v_10_0
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_aus_v_8_2
  - enterprise_linux_baseos_aus_v_8_4
  - enterprise_linux_baseos_aus_v_8_6
  - enterprise_linux_baseos_e4s_v_8_6
  - enterprise_linux_baseos_tus_v_8_6
  - enterprise_linux_baseos_e4s_v_8_8
  - enterprise_linux_baseos_tus_v_8_8
  - enterprise_linux_baseos_e4s_v_9_0
  - enterprise_linux_baseos_e4s_v_9_2
  - enterprise_linux_baseos_eus_v_9_4
  - enterprise_linux_baseos_v_9
  - compliance_operator 1
  - discovery 2
  - insights_proxy 1.5
  - openshift_distributed_tracing 3.6.0
  - openshift_sandboxed_containers 1.1
  - cert_manager_operator_for_red_hat_openshift 1.16
published: '2025-06-17'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:17:29.470'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6020'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:10024'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10027'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10180'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10354'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10357'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10358'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10359'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10361'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10362'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10735'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10823'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11386'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11487'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14557'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15099'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15709'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15827'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15828'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:16524'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:17181'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:18219'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:20181'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21885'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:22019'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9526'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:0934'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-6020'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2372512'
    label: secalert@redhat.com
  - url: >-
      https://github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx
    label: secalert@redhat.com
  - url: 'http://www.openwall.com/lists/oss-security/2025/06/17/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2025/09/msg00021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-577017.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6020.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-6020'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6020'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-06-17T13:30:00.379966Z'
epss: 0.0046
epssPercentile: 0.39069
ingestedAt: '2026-06-29T13:24:34.372Z'
---

## Overview

A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2025:10357** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS) · released 2025-07-07 · [advisory](https://access.redhat.com/errata/RHSA-2025:10357)
- **RHSA-2025:11386** · Red Hat · fixed in: Middleware Containers for OpenShift · released 2025-07-17 · [advisory](https://access.redhat.com/errata/RHSA-2025:11386)
- **RHSA-2026:0934** · Red Hat · fixed in: 8Base-Openshift-Serverless-1.36 · released 2026-01-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:0934)
- **RHSA-2025:15828** · Red Hat · fixed in: Red Hat Web Terminal 1.11 on RHEL 9 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15828)
- **RHSA-2025:15827** · Red Hat · fixed in: Red Hat Web Terminal 1.12 on RHEL 9 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15827)
- **RHSA-2025:22019** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0) · released 2025-11-25 · [advisory](https://access.redhat.com/errata/RHSA-2025:22019)
- **RHSA-2025:20181** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2025-11-11 · [advisory](https://access.redhat.com/errata/RHSA-2025:20181)
- **RHSA-2025:10354** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.0), Red Hat Enterprise Linux BaseOS E4S (v.9.0) · released 2025-07-07 · [advisory](https://access.redhat.com/errata/RHSA-2025:10354)
- **RHSA-2025:10180** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux BaseOS E4S (v.9.2) · released 2025-07-02 · [advisory](https://access.redhat.com/errata/RHSA-2025:10180)
- **RHSA-2025:10024** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.4), Red Hat Enterprise Linux BaseOS EUS (v.9.4) · released 2025-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2025:10024)
- **RHSA-2025:9526** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2025-06-24 · [advisory](https://access.redhat.com/errata/RHSA-2025:9526)
