First published: Tue Feb 18 2025(Updated: )
Last updated 26 February 2025
Credit: security@openanolis.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libcap2 | <=1:2.44-1<=1:2.66-4<=1:2.66-5 | 1:2.73-4 |
Libcap |
https://git.kernel.org/pub/scm/libs/libcap/libcap.git/commit/?id=1ad42b66c3567481cc5fa22fc1ba1556a31... https://git.kernel.org/pub/scm/libs/libcap/libcap.git/commit/
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1390 has a high severity due to the potential for unauthorized users to gain elevated capabilities.
To fix CVE-2025-1390, ensure that only trusted group names are used in the configuration and consider applying relevant patches from the libcap maintainers.
CVE-2025-1390 affects versions of libcap that improperly handle group names during configuration parsing.
CVE-2025-1390 can lead to unauthorized users being granted unintended capabilities, compromising system security.
As a temporary workaround for CVE-2025-1390, avoid using group names that do not start with '@' in the PAM module configurations.