Description

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.

INFO

Published Date :

2025-06-06T13:10:07.157Z

Last Modified :

2025-11-20T07:41:09.666Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-5791 vulnerability.

Vendors Products
Redhat
  • Confidential Compute Attestation
  • Enterprise Linux
  • Openshift
  • Trusted Profile Analyzer

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact