CVE-2024-2905: Red Hat Enterprise Linux 10

Medium severity, CVSS 6.2. EPSS: 0.3% chance of exploitation in the next 30 days.

A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit enabled. This issue arises from the default permissions being set at a higher level than recommended, potentially exposing sensitive authentication data to unauthorized access.

Affected products

  • Red Hat Red Hat Enterprise Linux 10: before 0:2025.5-1.el10 (fixed in 0:2025.5-1.el10)
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9: before 0:2024.3-3.el9_4 (fixed in 0:2024.3-3.el9_4)
  • Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 0:2023.3-2.el9_2 (fixed in 0:2023.3-2.el9_2)
  • Red Hat Red Hat Openshift Container Platform 4

Published 2024-04-25. Last modified 2026-06-17.