CVE-2025-6018: Pam-config: lpe from unprivileged to allow_active in pam
A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via SSH) to obtain the elevated privileges normally reserved for a physically present, "allowactive" user. The highest risk is that the attacker can then perform all allowactive yes Polkit actions, which are typically restricted to console users, potentially gaining unauthorized control over system configurations, services, or other sensitive operations.
Other sources
an LPE vulnerability (a Local Privilege Escalation) in the PAM configuration: an unprivileged local attacker (e.g., an attacker who logs in via sshd) can obtain the privileges of a physical "allowactive" user (i.e., a user who is physically sitting in front of the computer) and can therefore perform all the "allowactive yes" polkit actions that are normally reserved for physical users.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6018?
CVE-2025-6018 is classified with a high severity rating due to its potential for local privilege escalation.
How do I fix CVE-2025-6018?
To fix CVE-2025-6018, update the Linux Pluggable Authentication Modules (PAM) to the latest patched version available.
Who is affected by CVE-2025-6018?
CVE-2025-6018 primarily affects local users on systems that utilize Linux Pluggable Authentication Modules (PAM).
What kind of attack does CVE-2025-6018 enable?
CVE-2025-6018 enables an unprivileged local attacker to escalate their privileges on the system.
Is there a workaround for CVE-2025-6018?
Until a patch can be applied for CVE-2025-6018, limiting access to the affected systems and monitoring for unusual activity may help mitigate the risk.