CVE Vulnerabilities

CVE-2025-36244

External Initialization of Trusted Variables or Data Stores

Published: Sep 16, 2025 | Modified: Sep 16, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.

Weakness

The product initializes critical internal variables or data stores using inputs that can be modified by untrusted actors.

Potential Mitigations

References