CVE-2025-5467

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:*
cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:*

History

17 Dec 2025, 17:12

Type Values Removed Values Added
First Time Canonical
Canonical apport
CPE cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:*
References () https://bugs.launchpad.net/apport/+bug/2106338 - () https://bugs.launchpad.net/apport/+bug/2106338 - Exploit, Third Party Advisory
References () https://www.stratascale.com/resource/cve-2025-32462-ubuntu-apport-vulnerability/ - () https://www.stratascale.com/resource/cve-2025-32462-ubuntu-apport-vulnerability/ - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3

10 Dec 2025, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-10 18:16

Updated : 2025-12-17 17:12


NVD link : CVE-2025-5467

Mitre link : CVE-2025-5467

CVE.ORG link : CVE-2025-5467


JSON object : View

Products Affected

canonical

  • apport
CWE
CWE-708

Incorrect Ownership Assignment