CVE Vulnerabilities

CVE-2025-5467

Incorrect Ownership Assignment

Published: Dec 10, 2025 | Modified: Dec 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

It was discovered that process_crash() in data/apport in Canonicals Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.

Weakness

The product assigns an owner to a resource, but the owner is outside of the intended control sphere.

Potential Mitigations

References