boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-4598

Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   H   L   N  U  H  N  N    4.7   .0123   68.0     —
AFFECTED
  Product                      Versions     Fixed
  systemd-coredump             unspecified  —
  Red Hat Enterprise Linux 10  unspecified  0:257-23.el10
  Red Hat Enterprise Linux 9   unspecified  0:252-55.el9_7.7
  Red Hat Enterprise Linux 9   unspecified  0:252-55.el9_7.7
  Red Hat Ceph Storage 7       unspecified  7
  Red Hat Ceph Storage 8       unspecified  8
  Red Hat Ceph Storage 8       unspecified  1769512383
  Red Hat Discovery 2          unspecified  1767888970
  Red Hat Discovery 2          unspecified  1767904573
  Red Hat Insights proxy 1.5   unspecified  1.5.9-1765201856
  + 9 more
TIMELINE
  May 12  Reserved by redhat
  May 30  Published (CNA: redhat)
  Aug 21  EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.
  Aug 31  EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.
  Sep 1   EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.
CWE-364 · CNA: redhat · CVSS v3.1 · 19 references · NVD status: Modified

Description

A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.

Lifecycle

Complete event history — 5 events, chronological
DateEventDetail
May 12, 2025ReservedReserved by redhat
May 30, 2025PublishedPublished (CNA: redhat)
August 21, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.
August 31, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.
September 1, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.

Affected

Affected products and packages — 19 rows
VendorProduct / PackageEcosystemVersion introducedFixed
—systemd-coredump———
Red HatRed Hat Enterprise Linux 10——0:257-23.el10
Red HatRed Hat Enterprise Linux 9——0:252-55.el9_7.7
Red HatRed Hat Enterprise Linux 9——0:252-55.el9_7.7
Red HatRed Hat Ceph Storage 7——7
Red HatRed Hat Ceph Storage 8——8
Red HatRed Hat Ceph Storage 8——1769512383
Red HatRed Hat Discovery 2——1767888970
Red HatRed Hat Discovery 2——1767904573
Red HatRed Hat Insights proxy 1.5——1.5.9-1765201856
Red HatRed Hat Enterprise Linux 10———
Red HatRed Hat Enterprise Linux 10———
Red HatRed Hat Enterprise Linux 7———
Red HatRed Hat Enterprise Linux 7———
Red HatRed Hat Enterprise Linux 8———
Red HatRed Hat Enterprise Linux 9———
Red HatRed Hat OpenShift Container Platform 4———
Red HatRed Hat OpenShift Container Platform 4———
Red HatRed Hat OpenShift Container Platform 4———

Weaknesses

CWE-364

References (19)

Related

Authoritative record: CVE-2025-4598 at cve.org

Vendors: red hat

Weaknesses: CWE-364

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-4598 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.