CVE-2025-6020
Executive Summary
CVE-2025-6020: The pam_namespace module in Linux PAM can be tricked into following user-specified paths. By crafting symlinks and exploiting race conditions, a local user can cause the module to open privileged files, enabling privilege escalation to root. No KEV listing yet.
Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2025-06-17T13:15:21.660 - Last Modified: 2026-09-05T16:17:21.147
Original Description: A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.
"He who talks more is sooner exhausted."
— Lao Tzu
Source: NVD