Critical Linux Vulnerabilities Risk Password Theft and Privilege Escalation
The Qualys Threat Research Unit has revealed two critical local information disclosure vulnerabilities, CVE-2025-5054 and CVE-2025-4598, affecting the core dump handlers Apport and systemd-coredump across various Linux distributions. These vulnerabilities could enable local attackers to extract sensitive information, including password hashes, from systems running Ubuntu, Red Hat Enterprise Linux, and Fedora.