CVE-2025-53881: SUSE-specific logrotate configuration allows escalation from mail user/group to root
Published Oct 2, 2025
·Updated
A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalation from mail user/group to root.This issue affects Tumbleweed: from ? before 4.98.2-lp156.248.1.
Affected Software
1 affected component
SUSE exim<4.98.2-lp156.248.1
Event History
Oct 2, 2025
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-53881?
The severity of CVE-2025-53881 is considered high due to its potential for privilege escalation.
2
How do I fix CVE-2025-53881?
To fix CVE-2025-53881, upgrade your SUSE exim package to version 4.98.2-lp156.248.1 or later.
3
Which systems are affected by CVE-2025-53881?
CVE-2025-53881 affects SUSE exim versions prior to 4.98.2-lp156.248.1.
4
What type of vulnerability is CVE-2025-53881?
CVE-2025-53881 is a UNIX Symbolic Link (Symlink) Following vulnerability.
5
What are the consequences of CVE-2025-53881?
The consequences of CVE-2025-53881 include the potential for privilege escalation from the mail user/group to root.