Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-5791

Опубликовано: 15 янв. 2025
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rust-ssh-key-dirWill not fix
Red Hat Enterprise Linux 9rust-afterburnWill not fix
Red Hat OpenShift Container Platform 4kata-containersAffected
Red Hat OpenShift Container Platform 4rust-afterburnWill not fix
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2370001users: `root` appended to group listings

EPSS

Процентиль: 0%
0.00006
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
12 дней назад

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.

CVSS3: 7.1
nvd
12 дней назад

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.

CVSS3: 7.1
github
14 дней назад

users may append `root` to group listings

EPSS

Процентиль: 0%
0.00006
Низкий

7.1 High

CVSS3