CVE-2025-23394: daily-backup.sh script in cyrus-imapd allows escalation from cyrus to root
Published May 26, 2025
·Updated
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1.
Affected Software
1 affected component
openSUSE cyrus-imapd<3.8.4-2.1
Event History
May 26, 2025
CVE Published
via MITRE·03:34 PM
Data Sourced
via MITRE·03:34 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-23394?
CVE-2025-23394 is considered a high-severity vulnerability due to its potential for privilege escalation from cyrus to root.
2
How do I fix CVE-2025-23394?
To fix CVE-2025-23394, upgrade cyrus-imapd to version 3.8.4-2.1 or later.
3
Which versions of cyrus-imapd are affected by CVE-2025-23394?
CVE-2025-23394 affects all versions of cyrus-imapd prior to 3.8.4-2.1 in openSUSE Tumbleweed.
4
What does CVE-2025-23394 exploit?
CVE-2025-23394 exploits a UNIX Symbolic Link (Symlink) Following vulnerability.
5
Is my system vulnerable to CVE-2025-23394?
If you are using an openSUSE Tumbleweed version with cyrus-imapd before 3.8.4-2.1, your system is vulnerable to CVE-2025-23394.