CVE-2025-5054: Race Condition in Canonical Apport
Published May 30, 2025
·Updated
Last updated 26 August 2025
Other sources
Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces.
— Launchpad
Affected Software
9 affected components
Canonical apport<=2.32.0
Canonical apport<=2.32.0
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Canonical Ubuntu Linux=22.04
Canonical Ubuntu Linux=24.04
Canonical Ubuntu Linux=24.10
Canonical Ubuntu Linux=25.04
Event History
May 30, 2025
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 7, 2025
Data Sourced
via Debian·05:48 PM
DescriptionAffected Software
Aug 22, 2025
Data Sourced
via Launchpad·07:44 PM
Description
Aug 26, 2025
Data Sourced
via Ubuntu·07:43 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-5054?
CVE-2025-5054 has been classified with a medium severity rating due to its potential for exposing sensitive information.
2
How do I fix CVE-2025-5054?
To mitigate CVE-2025-5054, update Canonical Apport to version 2.32.1 or later.
3
What versions of Canonical Apport are affected by CVE-2025-5054?
CVE-2025-5054 affects Canonical Apport versions up to and including 2.32.0.
4
What is the nature of the vulnerability identified in CVE-2025-5054?
CVE-2025-5054 describes a race condition that allows a local attacker to leak sensitive information via PID-reuse.
5
Can CVE-2025-5054 be exploited remotely?
CVE-2025-5054 requires local access to exploit the vulnerability, meaning it cannot be exploited remotely.