CVE-2025-8941: Linux-pam: incomplete fix for cve-2025-6020
Telemetry drift only. No threshold crossed and no authority ruling changed.
CVE record loaded 2026-09-20.
What to do now held facts and links
- No fix version is held. The CNA's first reference is the place to look: access.redhat.com
- Record your decision, dated and frozen with today's evidence: patch by a date · mitigated by a compensating control · deferred · accepted the risk · not affected
- Check your version against the ranges this record publishes.
What it is stated by the CNA
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
- weakness
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- affected
- Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Web Terminal 1.11 on RHEL 9; Red Hat Web Terminal 1.12 on RHEL 9; Red Hat cert-manager operator for Red Hat OpenShift 1.16; Red Hat Compliance Operator 1; Red Hat Discovery 2; Red Hat Insights proxy 1.5; Red Hat OpenShift sandboxed containers 1.1
- versions
- The CVE record states its affected versions as source commits, wildcards or bare build numbers, not as versions that can be compared. None are printed here.
- fixed in
- No fix version in held sources.
- severity
- 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- assigned by
- redhat
- published
- 2025-08-13
check us access.redhat.com access.redhat.com access.redhat.com access.redhat.com
Exploit code held, dated
- exploit code
- None held in the PoC-in-GitHub feed. A public repository changes this brief.
What moved held, dated
| date | EPSS | event |
|---|---|---|
| 14 Aug 2025 | 0.00022 | |
| 19 Aug 2025 | 0.00025 | |
| 1 Sep 2025 | 0.00023 | |
| 3 Sep 2025 | 0.00024 | |
| 9 Jun 2026 | 0.00059 | |
| 15 Jun 2026 | 0.00254 | scoring model v2026.06.15 |
| 14 Jul 2026 | 0.00264 | |
| 2 Sep 2026 | 0.0027 |
25 observations held. A step marked with a scoring model moved because the measurement was replaced, not because the vulnerability changed.
Outside the record researched, cited
This section reads the record's references and adds cited findings from outside it. It needs an account. Everything above is held facts and is complete without it.
What would change this brief held, dated
- CISA KEV
- Not listed in the catalogue we hold. A listing changes this brief.
- exploit probability
- 0.00 on 2026-09-02 (FIRST's EPSS, a probability and not evidence of exploitation). Next band line: 10% (0.10). Crossing a line changes this brief.
- fix
- No fix version is held. One published by the CNA or OSV changes this brief.
How to check this
Every value above is held with two dates: when it was true upstream (as_of) and when we recorded it (tx_from). Re-derive the exploit probability as it stood on any date:
SELECT value, source, source_version, as_of, tx_from
FROM volatile_valid_as_of('CVE-2025-8941', '2026-10-03T23:59:59.999999Z', now());Identity above is quoted from the CVE Program record, corpus cvelistv5_20260920, recorded 30 Sep 2026.