CVE-2025-23386: gerbera: Privilege escalation from user gerbera to root because of insecure %post script
A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This issue affects gerbera on openSUSE Tumbleweed before 2.5.0-1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23386?
CVE-2025-23386 is classified as a high severity vulnerability due to the potential for privilege escalation to root access.
How do I fix CVE-2025-23386?
To fix CVE-2025-23386, upgrade the gerbera package to version 2.5.0-1.1 or later on openSUSE Tumbleweed.
What systems are affected by CVE-2025-23386?
CVE-2025-23386 affects openSUSE Tumbleweed installations running gerbera versions prior to 2.5.0-1.1.
What is the nature of the vulnerability described in CVE-2025-23386?
CVE-2025-23386 is an Incorrect Default Permissions vulnerability that allows the gerbera service user to escalate permissions to root.
Is there a workaround for CVE-2025-23386?
Currently, the best course of action for CVE-2025-23386 is to update to the patched version, as no known effective workaround exists.