CVE Vulnerabilities

CVE-2025-36244

External Initialization of Trusted Variables or Data Stores

Published: Sep 16, 2025 | Modified: Oct 17, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.

Weakness

The product initializes critical internal variables or data stores using inputs that can be modified by untrusted actors.

Affected Software

NameVendorStart VersionEnd Version
ViosIbm3.1 (including)3.1 (including)
ViosIbm4.1 (including)4.1 (including)
AixIbm7.2 (including)7.2 (including)
AixIbm7.3 (including)7.3 (including)

Potential Mitigations

References