CVE-2025-8941: Red Hat Cert-Manager Operator For Red Hat Openshift 1.16
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.
Affected products
- Red Hat Cert-Manager Operator For Red Hat Openshift 1.16
- Red Hat Compliance Operator 1
- Red Hat Red Hat Discovery 2
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:1.1.8-23.el7_9.2 (fixed in 0:1.1.8-23.el7_9.2)
- Red Hat Red Hat Enterprise Linux 8: before 0:1.3.1-38.el8_10 (fixed in 0:1.3.1-38.el8_10)
- Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support: before 0:1.3.1-8.el8_2.2 (fixed in 0:1.3.1-8.el8_2.2)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:1.3.1-14.el8_4.2 (fixed in 0:1.3.1-14.el8_4.2)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:1.3.1-14.el8_4.2 (fixed in 0:1.3.1-14.el8_4.2)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:1.3.1-16.el8_6.3 (fixed in 0:1.3.1-16.el8_6.3)
- Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 0:1.3.1-16.el8_6.3 (fixed in 0:1.3.1-16.el8_6.3)
- Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 0:1.3.1-16.el8_6.3 (fixed in 0:1.3.1-16.el8_6.3)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:1.3.1-26.el8_8.2 (fixed in 0:1.3.1-26.el8_8.2)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:1.3.1-26.el8_8.2 (fixed in 0:1.3.1-26.el8_8.2)
- Red Hat Red Hat Enterprise Linux 9: before 0:1.5.1-26.el9_6 (fixed in 0:1.5.1-26.el9_6)
- Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:1.5.1-9.el9_0.3 (fixed in 0:1.5.1-9.el9_0.3)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:1.5.1-15.el9_2.2 (fixed in 0:1.5.1-15.el9_2.2)
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:1.5.1-24.el9_4.1 (fixed in 0:1.5.1-24.el9_4.1)
- Red Hat Red Hat Insights Proxy 1.5
- Red Hat Red Hat Openshift Sandboxed Containers 1.1
- Red Hat Red Hat Web Terminal 1.11 On Rhel 9: before 1.11-19 (fixed in 1.11-19); before 1.11-8 (fixed in 1.11-8)
- Red Hat Red Hat Web Terminal 1.12 On Rhel 9: before 1.12-4 (fixed in 1.12-4)
Published 2025-08-13. Last modified 2026-06-17.