CVE-2025-1390 - CVE House
Back to Database
Status published Medium CVE-2025-1390

pam_cap: Fix potential configuration parsing error

Vulnerability Description

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1390

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Tianjia Zhang <tianjia.zhang@linux.alibaba.com>

Affected Vendor

Affected Software

Anolis OS
Vulnerable Versions:
2.73;0

Timeline

Official Publish: February 18th, 2025
Last Modified: February 18th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

Weaknesses (CWE)