REDHAT-BUG-2369242: Medium severity systemd systemd-coredump vulnerability
Published May 29, 2025
·Updated
A race condidition in systemd-coredump allows a local attacker to crash a SUID program and gain read access to the resulting core dump
Affected Software
1 affected component
systemd systemd-coredump
Event History
May 29, 2025
Data Sourced
via Red Hat·07:07 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2369242?
The severity of REDHAT-BUG-2369242 is considered high due to its potential to allow local attackers to exploit a race condition.
2
How do I fix REDHAT-BUG-2369242?
To fix REDHAT-BUG-2369242, you should promptly update your systemd-coredump package to the latest version provided by your distribution.
3
Who is affected by REDHAT-BUG-2369242?
Any system using systemd-coredump that allows SUID programs may be affected by REDHAT-BUG-2369242.
4
What can an attacker do with REDHAT-BUG-2369242?
An attacker can exploit REDHAT-BUG-2369242 to crash SUID programs and gain unauthorized read access to the core dumps.
5
Is there a workaround for REDHAT-BUG-2369242?
As a workaround for REDHAT-BUG-2369242, consider disabling SUID programs until the systemd-coredump package is updated.