Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2025-4598
Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump
AV AC PR UI S C I A CVSS EPSS %ile KEV
L H L N U H N N 4.7 .0123 68.0 —
AFFECTED
Product Versions Fixed
systemd-coredump unspecified —
Red Hat Enterprise Linux 10 unspecified 0:257-23.el10
Red Hat Enterprise Linux 9 unspecified 0:252-55.el9_7.7
Red Hat Enterprise Linux 9 unspecified 0:252-55.el9_7.7
Red Hat Ceph Storage 7 unspecified 7
Red Hat Ceph Storage 8 unspecified 8
Red Hat Ceph Storage 8 unspecified 1769512383
Red Hat Discovery 2 unspecified 1767888970
Red Hat Discovery 2 unspecified 1767904573
Red Hat Insights proxy 1.5 unspecified 1.5.9-1765201856
+ 9 more
TIMELINE
May 12 Reserved by redhat
May 30 Published (CNA: redhat)
Aug 21 EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.
Aug 31 EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.
Sep 1 EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.
Description
A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.
A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.
Lifecycle
Complete event history — 5 events, chronological
| Date | Event | Detail |
| May 12, 2025 | Reserved | Reserved by redhat |
| May 30, 2025 | Published | Published (CNA: redhat) |
| August 21, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added. |
| August 31, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added. |
| September 1, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added. |
Affected
Affected products and packages — 19 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| — | systemd-coredump | — | — | — |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | 0:257-23.el10 |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | 0:252-55.el9_7.7 |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | 0:252-55.el9_7.7 |
| Red Hat | Red Hat Ceph Storage 7 | — | — | 7 |
| Red Hat | Red Hat Ceph Storage 8 | — | — | 8 |
| Red Hat | Red Hat Ceph Storage 8 | — | — | 1769512383 |
| Red Hat | Red Hat Discovery 2 | — | — | 1767888970 |
| Red Hat | Red Hat Discovery 2 | — | — | 1767904573 |
| Red Hat | Red Hat Insights proxy 1.5 | — | — | 1.5.9-1765201856 |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 7 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 7 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | — | — | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | — | — | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-4598 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.