CVE-2025-5467: Canonical Apport
Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.
It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.
Affected products
- Canonical Apport: from 2.20.1-0ubuntu1, before 2.20.1-0ubuntu2.30 (fixed in 2.20.1-0ubuntu2.30); from 2.20.9-0ubuntu7, before 2.20.9-0ubuntu7.29 (fixed in 2.20.9-0ubuntu7.29); from 2.20.11-0ubuntu27, before 2.20.11-0ubuntu27.28 (fixed in 2.20.11-0ubuntu27.28); from 2.20.11-0ubuntu82, before 2.20.11-0ubuntu82.7 (fixed in 2.20.11-0ubuntu82.7); from 2.28.1-0ubuntu1, before 2.28.1-0ubuntu3.6 (fixed in 2.28.1-0ubuntu3.6); from 2.32.0-0ubuntu1, before 2.32.0-0ubuntu5.1 (fixed in 2.32.0-0ubuntu5.1)
Published 2025-12-10. Last modified 2026-06-17.