CVE-2025-5467

Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
10/12/2025
Last modified:
17/12/2025

Description

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:* 2.20.1-0ubuntu1 (including) 2.20.1-0ubuntu2.30 (excluding)
cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:* 2.20.9-0ubuntu7 (including) 2.20.9-0ubuntu7.29 (excluding)
cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:* 2.20.11-0ubuntu27 (including) 2.20.11-0ubuntu27.28 (excluding)
cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:* 2.20.11-0ubuntu82 (including) 2.20.11-0ubuntu82.7 (excluding)
cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:* 2.28.1-0ubuntu1 (including) 2.28.1-0ubuntu3.6 (excluding)
cpe:2.3:a:canonical:apport:*:*:*:*:*:*:*:* 2.32.0-0ubuntu1 (including) 2.32.0-0ubuntu5.1 (excluding)