# CVE-2025-6020

## Summary

- **CVE ID:** CVE-2025-6020
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-22
- **Published:** Jun 17, 2025
- **Last Modified:** Sep 8, 2026

## Description

A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.

## Affected Products

- Unknown product (0)
- Red Hat — Red Hat Enterprise Linux 10 (0:1.6.1-8.el10)
- Red Hat — Red Hat Enterprise Linux 10.0 Extended Update Support (0:1.6.1-8.el10_0)
- Red Hat — Red Hat Enterprise Linux 7 Extended Lifecycle Support (0:1.1.8-23.el7_9.1)
- Red Hat — Red Hat Enterprise Linux 8 (0:1.3.1-37.el8_10)
- Red Hat — Red Hat Enterprise Linux 8 (0:1.3.1-38.el8_10)
- Red Hat — Red Hat Enterprise Linux 8.2 Advanced Update Support (0:1.3.1-8.el8_2.1)
- Red Hat — Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support (0:1.3.1-14.el8_4.1)
- Red Hat — Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support (0:1.3.1-16.el8_6.2)
- Red Hat — Red Hat Enterprise Linux 8.6 Telecommunications Update Service (0:1.3.1-16.el8_6.2)
- Red Hat — Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions (0:1.3.1-16.el8_6.2)
- Red Hat — Red Hat Enterprise Linux 8.8 Telecommunications Update Service (0:1.3.1-26.el8_8.1)
- Red Hat — Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions (0:1.3.1-26.el8_8.1)
- Red Hat — Red Hat Enterprise Linux 9 (0:1.5.1-26.el9_6)
- Red Hat — Red Hat Enterprise Linux 9 (0:1.5.1-25.el9_6)
- Red Hat — Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions (0:1.5.1-9.el9_0.2)
- Red Hat — Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions (0:1.5.1-15.el9_2.1)
- Red Hat — Red Hat Enterprise Linux 9.4 Extended Update Support (0:1.5.1-24.el9_4)
- Red Hat — Red Hat Web Terminal 1.11 on RHEL 9 (1.11-19)
- Red Hat — Red Hat Web Terminal 1.11 on RHEL 9 (1.11-8)
- Red Hat — Red Hat Web Terminal 1.12 on RHEL 9 (1.12-4)
- Red Hat — RHEL-8 based Middleware Containers (7.13.5-4.1752066672)
- Red Hat — RHEL-8 based Middleware Containers (7.13.5-4.1752065732)
- Red Hat — RHEL-8 based Middleware Containers (7.13.5-3.1752065737)
- Red Hat — RHEL-8 based Middleware Containers (7.13.5-4.1752065731)
- Red Hat — RHEL-8 based Middleware Containers (7.13.5-25)
- Red Hat — RHEL-8 based Middleware Containers (7.13.5-4.1752065736)
- Red Hat — RHEL-8 based Middleware Containers (7.13.5-2.1752065733)
- Red Hat — RHEL-8 based Middleware Containers (7.13.5-4.1752065755)
- Red Hat — RHOSS-1.36-RHEL-8 (1.36.0-11)
- Red Hat — RHOSS-1.36-RHEL-8 (1.36.0-10)
- Red Hat — RHOSS-1.36-RHEL-8 (1.36.0-4)
- Red Hat — RHOSS-1.36-RHEL-8 (1.36.0-9)
- Red Hat — RHOSS-1.36-RHEL-8 (1.36.0-12)
- Red Hat — RHOSS-1.36-RHEL-8 (1.36.0-18)
- Red Hat — RHOSS-1.36-RHEL-8 (1.36.0-7)
- Red Hat — cert-manager operator for Red Hat OpenShift 1.16 (sha256:1abdfac084e7c86e7a93a19e5cf6b54db79b903bfb7474a42200f753b29eda4b)
- Red Hat — Compliance Operator 1 (sha256:06ad8599c4b0170264e40a45b0126504c87c37f0832265c7ff6541d2385b2049)
- Red Hat — Red Hat Discovery 2 (sha256:bd9cb502def3153c193713b56372694cb555a71b38d4fc0fd9d021bccc5602de)
- Red Hat — Red Hat Discovery 2 (sha256:c85cfbcaf7888885e57596b7b8bde3894718cfc33326499b24961a66a62cf083)
- Red Hat — Red Hat Insights proxy 1.5 (sha256:4ca38b33efec0d2dd17a8fd822a7c18281810676ceabb0c1db90953cb91cd5ea)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:40535c017d2730645c57c44b32b4df1613585cc19c052fe472ccbf543a659c42)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:5bb83d0b9387f51291c3977d37aab8a19e978a7dccf3d72cae0dabb66bd26df4)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:f49a121a3d0ec81f510680cd47c552f82c48889f28d3f14037c582636085410a)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:f370f7f76c96e27bd5cd93b993d850c8ce5123a2dc1a03955596db5eee88d411)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:e8f3e4113f56564a287bad34721440b00ef600fb99f0dc454dd9c9581e57e696)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:b9af5a1af9342d62f300d970c0894b483eaaa4082ea9903d99e7267637b68f59)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:fb1e2c0ad417d391d2fe055e68e9aadd5b24b2c99f3fe5895750579e537fdc7d)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:9eaae087bccf2cedfea26d1c0235cfbbe227f9b8f1eda67dc0b33441e319eb85)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:cbfcac41c1bd3a06e874433089e231dfd2a944dee139906d9949e2d68b71cfc3)
- Red Hat — Red Hat OpenShift sandboxed containers 1.1 (sha256:7b6bd3411ca5ec140968975d4f11f3ec0686b6fbca0ce05288e041ee2e569a89)
- Red Hat — Red Hat OpenShift sandboxed containers 1.1 (sha256:f5e1602d72177d77f1b879c76e6f6cfbc2979c136c06ca9f03ea97ffb369b7a6)
- Red Hat — Red Hat OpenShift sandboxed containers 1.1 (sha256:cead623ceda4048cabaa81c371ed2a8143f5c5514276fca1d71685bd9e6d1e65)
- Red Hat — Red Hat OpenShift sandboxed containers 1.1 (sha256:59fb1f7f1653361d94f7d48b42d8fe19ed3263c1c78654837c11f2135544c1ac)
- Red Hat — cert-manager operator for Red Hat OpenShift 1.16 (sha256:330e8b5ab4841a21f8f5f23cc7fb192197872f11639b12bf4b1e70831f636323)
- Red Hat — Compliance Operator 1 (sha256:c953e9f9abf9cf25bf65bb3ffdc86ccf49b3e69a1cf3fbb47b6972e421fd6628)
- Red Hat — Red Hat Discovery 2 (sha256:c499a099e03c7488ffe50529a34723ade191a89fcfc59d1f0edd01db2b579ca3)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:c18d414518b1eaed33a17a13f6c0273ab14405dd9569c169e6839026330e0895)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:46090c79b193de2028b4c994d3013fec7102f3b10673ecd09b017be4de7bf9f6)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:3d281c9d7fe151c35605aac57a95fec699d20ecea6f4a5ea5b8cdc26a8808695)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:d1425fca630adab3f66b30eaf47010c2da892e2d635a721c493c1751f98f69b3)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:c34a7574e3c6af4c82bee38e581d047613f8931c12d89924764f46b565bf3117)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:1feaee0df48953c919df3ceb2dde3aa10345e69c0b1a7186a8a0fd6ab9b300f6)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:d0783f1725e2452c74dd687ac3238634851b9e587cd5c1134e790a43cdd7cad5)
- Red Hat — Red Hat OpenShift sandboxed containers 1.1 (sha256:8f29671308ca658e32e97d5c3b482f7541aae1bca1b71f39b3276a9a334d8108)
- Red Hat — Red Hat Discovery 2 (sha256:1c67d8d526ab4f2854947f7dccd8752a2efd414c0f1cbab17706fa91147e7cda)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:1faa5daf085b0844740653d96711b3fcfa766a77224fb523335d877b8e314b57)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:39378c1e705973edca5f52f422b5c3693aaf5d2f22fb320d7676086b2cf846ba)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:18ca3c44f6f25cbfe67842a0b2c9491a8247a64dbd166f188dccf0a84cfd3e67)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:34851d4dd94a887b27d0937a1238d09ac370b4ec06382fe880796dac86c4aa3e)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:2a37885dbd9735167854119a546f9ce1b37454a2b57d283fbd8da890c01db767)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:8f2da1e0fc45a36cffbe91f9a1c4449eb0c71671865b7194951ad727c9f7b064)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (sha256:54c5403a8a9e0300233e75a04318013e9dbe3d894be691927d27dc2fe53fddc0)
- Red Hat — Red Hat OpenShift sandboxed containers 1.1 (sha256:24722900db1425bf0c27f6ad6f3fb7d79ff9ebc433bdab58423fa71bab76122b)
- Red Hat — Red Hat OpenShift sandboxed containers 1.1 (sha256:9ff002e628e5646b5ab3cc9201087847bea29569b4a1bc135b89d5c1a5f0a422)
- Red Hat — OpenShift Compliance Operator 1 (sha256:06ad8599c4b0170264e40a45b0126504c87c37f0832265c7ff6541d2385b2049)
- Red Hat — cert-manager operator for Red Hat OpenShift 1.16 (v1.16.5-1760515757)
- Red Hat — OpenShift Compliance Operator 1 (1.8.0)
- Red Hat — Red Hat Discovery 2 (2.0.0-1752592913)
- Red Hat — Red Hat Discovery 2 (2.2.1-1758555934)
- Red Hat — Red Hat Insights proxy 1.5 (1.5.7-1759331989)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (rhosdt-3.6-1752046452)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (rhosdt-3.6-1752046437)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (rhosdt-3.6-1752046439)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (rhosdt-3.6-1752070865)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (rhosdt-3.6-1752070873)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (rhosdt-3.6-1751993590)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (rhosdt-3.6-1752070827)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (rhosdt-3.6-1752070833)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.0 (rhosdt-3.6-1752070866)
- Red Hat — Red Hat OpenShift sandboxed containers 1.1 (1.10.2-1757422110)
- Red Hat — Red Hat OpenShift sandboxed containers 1.1 (1.10.2-1757421804)
- Red Hat — Red Hat OpenShift sandboxed containers 1.1 (1.10.2-1757421879)
- Red Hat — Red Hat OpenShift sandboxed containers 1.1 (1.10.2-1757422401)
- Red Hat — Compliance Operator 1 (1.8.0)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.1 (rhosdt-3.6-1752046452)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.1 (rhosdt-3.6-1752046437)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.1 (rhosdt-3.6-1752046439)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.1 (rhosdt-3.6-1752070865)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.1 (rhosdt-3.6-1752070873)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.1 (rhosdt-3.6-1751993590)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.1 (rhosdt-3.6-1752070827)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.1 (rhosdt-3.6-1752070833)
- Red Hat — Red Hat OpenShift distributed tracing 3.6.1 (rhosdt-3.6-1752070866)

## References

- [CNA](https://access.redhat.com/errata/RHSA-2025:10024)
- [CNA](https://access.redhat.com/errata/RHSA-2025:10027)
- [CNA](https://access.redhat.com/errata/RHSA-2025:10180)
- [CNA](https://access.redhat.com/errata/RHSA-2025:10354)
- [CNA](https://access.redhat.com/errata/RHSA-2025:10357)
- [CNA](https://access.redhat.com/errata/RHSA-2025:10358)
- [CNA](https://access.redhat.com/errata/RHSA-2025:10359)
- [CNA](https://access.redhat.com/errata/RHSA-2025:10361)
- [CNA](https://access.redhat.com/errata/RHSA-2025:10362)
- [CNA](https://access.redhat.com/errata/RHSA-2025:10735)
- [CNA](https://access.redhat.com/errata/RHSA-2025:10823)
- [CNA](https://access.redhat.com/errata/RHSA-2025:11386)
- [CNA](https://access.redhat.com/errata/RHSA-2025:11487)
- [CNA](https://access.redhat.com/errata/RHSA-2025:14557)
- [CNA](https://access.redhat.com/errata/RHSA-2025:15099)
- [CNA](https://access.redhat.com/errata/RHSA-2025:15709)
- [CNA](https://access.redhat.com/errata/RHSA-2025:15827)
- [CNA](https://access.redhat.com/errata/RHSA-2025:15828)
- [CNA](https://access.redhat.com/errata/RHSA-2025:16524)
- [CNA](https://access.redhat.com/errata/RHSA-2025:17181)
- [CNA](https://access.redhat.com/errata/RHSA-2025:18219)
- [CNA](https://access.redhat.com/errata/RHSA-2025:20181)
- [CNA](https://access.redhat.com/errata/RHSA-2025:21885)
- [CNA](https://access.redhat.com/errata/RHSA-2025:22019)
- [CNA](https://access.redhat.com/errata/RHSA-2025:9526)
- [CNA](https://access.redhat.com/errata/RHSA-2026:0934)
- [CNA](https://access.redhat.com/security/cve/CVE-2025-6020)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2372512)
- [CVE](http://www.openwall.com/lists/oss-security/2025/06/17/1)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/09/msg00021.html)
- [CNA](https://github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-577017.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.44%
- **EPSS Percentile:** 37.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._