Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-71239

Опубликовано: 17 мар. 2026
Источник: redhat
CVSS3: 5.1
EPSS Низкий

Описание

No description is available for this CVE.

Отчет

Audit change attribute rules did not cover fchmodat2 so chmod like attribute changes performed via fchmodat2 could bypass file watch audit rules. For the CVSS the PR:N is used in the paranoid case because unprivileged users can typically call fchmodat2 on files they own. Unlikely that actual until in the hardened environments where audit logs are used for compliance alerting and incident response.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-693
https://bugzilla.redhat.com/show_bug.cgi?id=2448336kernel: audit: add fchmodat2() to change attributes class

EPSS

Процентиль: 9%
0.00032
Низкий

5.1 Medium

CVSS3

Связанные уязвимости

ubuntu
12 дней назад

[audit: add fchmodat2() to change attributes class]

nvd
12 дней назад

In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class fchmodat2(), introduced in version 6.6 is currently not in the change attribute class of audit. Calling fchmodat2() to change a file attribute in the same fashion than chmod() or fchmodat() will bypass audit rules such as: -w /tmp/test -p rwa -k test_rwa The current patch adds fchmodat2() to the change attributes class.

CVSS3: 5.5
msrc
11 дней назад

audit: add fchmodat2() to change attributes class

debian
12 дней назад

In the Linux kernel, the following vulnerability has been resolved: a ...

github
12 дней назад

In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class fchmodat2(), introduced in version 6.6 is currently not in the change attribute class of audit. Calling fchmodat2() to change a file attribute in the same fashion than chmod() or fchmodat() will bypass audit rules such as: -w /tmp/test -p rwa -k test_rwa The current patch adds fchmodat2() to the change attributes class.

EPSS

Процентиль: 9%
0.00032
Низкий

5.1 Medium

CVSS3