CVE-2024-2905: Red Hat Enterprise Linux 10
Medium severity, CVSS 6.2. EPSS: 0.3% chance of exploitation in the next 30 days.
A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit enabled. This issue arises from the default permissions being set at a higher level than recommended, potentially exposing sensitive authentication data to unauthorized access.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 0:2025.5-1.el10 (fixed in 0:2025.5-1.el10)
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9: before 0:2024.3-3.el9_4 (fixed in 0:2024.3-3.el9_4)
- Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 0:2023.3-2.el9_2 (fixed in 0:2023.3-2.el9_2)
- Red Hat Red Hat Openshift Container Platform 4
Published 2024-04-25. Last modified 2026-06-17.