Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-5791

Опубликовано: 06 июн. 2025
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.

EPSS

Процентиль: 1%
0.00008
Низкий

7.1 High

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 7.1
ubuntu
8 месяцев назад

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.

CVSS3: 7.1
redhat
около 1 года назад

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.

CVSS3: 7.1
msrc
6 месяцев назад

Users: `root` appended to group listings

CVSS3: 7.1
github
8 месяцев назад

users may append `root` to group listings

CVSS3: 7.1
fstec
около 1 года назад

Уязвимость языка программирования Rust, связанная с некорректным присваиванием привилегий, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 1%
0.00008
Низкий

7.1 High

CVSS3

Дефекты

CWE-266