VDB
RHSA-2025%3A22868
RHSA-2025%3A22868
PUBLISHED
CVSS 3.5999999046325684 LOW
A flaw was found in shadow-utils. Affected versions of shadow-utils establish a default /etc/subuid behavior, for example, uid 100000 through 165535 for the first user account, that can conflict with the uids of users defined on locally administered networks. This issue potentially leads to account takeover by leveraging newuidmap for access to an NFS home directory or same-host resources for remote logins by these local network users.
Risk Scores
CVSS 3.1
3.5999999046325684
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:1d72e553fe5a7696e600dc8fd2fe9050ba1992fa190bea622134ca7bfce7bb0d_arm64 as a component of Red Hat Insights proxy 1.5 | registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:1d72e553fe5a7696e600dc8fd2fe9050ba1992fa190bea622134ca7bfce7bb0d_arm64, registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:1d72e553fe5a7696e600dc8fd2fe9050ba1992fa190bea622134ca7bfce7bb0d_arm64, registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:1d72e553fe5a7696e600dc8fd2fe9050ba1992fa190bea622134ca7bfce7bb0d_arm64 |
| Red Hat | registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:1d72e553fe5a7696e600dc8fd2fe9050ba1992fa190bea622134ca7bfce7bb0d_arm64 as a component of Red Hat Insights proxy 1.5 | registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:1d72e553fe5a7696e600dc8fd2fe9050ba1992fa190bea622134ca7bfce7bb0d_arm64, * |
| Red Hat | registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:345d8bc236043df01ce0557357d20fa443719dc943038f9648cfac0c5a465cfe_amd64 as a component of Red Hat Insights proxy 1.5 | registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:345d8bc236043df01ce0557357d20fa443719dc943038f9648cfac0c5a465cfe_amd64, registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:345d8bc236043df01ce0557357d20fa443719dc943038f9648cfac0c5a465cfe_amd64, registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:345d8bc236043df01ce0557357d20fa443719dc943038f9648cfac0c5a465cfe_amd64 |
| Red Hat | registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:345d8bc236043df01ce0557357d20fa443719dc943038f9648cfac0c5a465cfe_amd64 as a component of Red Hat Insights proxy 1.5 | registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:345d8bc236043df01ce0557357d20fa443719dc943038f9648cfac0c5a465cfe_amd64, * |
Timeline
- Dec 8, 2025 CVE Published
- Apr 24, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 11, 2026 CVE Updated
- May 11, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:22868 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22868.json advisory
- https://www.cve.org/CVERecord?id=CVE-2024-56433 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-6965 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2392605 issue
- https://gitlab.gnome.org/GNOME/libxslt/-/issues/148 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2380362 issue
- https://github.com/vim/vim/commit/586294a04179d855c3d1d4ee5ea83931963680b8 advisory
- https://access.redhat.com/security/cve/CVE-2025-4598 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-56433 advisory
- https://github.com/shadow-maint/shadow/issues/1157 advisory
- https://github.com/shadow-maint/shadow/releases/tag/4.4 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-4598 advisory
- https://www.openwall.com/lists/oss-security/2025/05/29/3 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-53905 advisory
- https://github.com/vim/vim/commit/87757c6b0a4b2c1f71c72ea8e1438b8fb116b239 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-53906 advisory
- https://access.redhat.com/security/cve/CVE-2024-56433 advisory
- https://access.redhat.com/security/cve/CVE-2025-6965 advisory
- https://access.redhat.com/security/cve/CVE-2025-9714 advisory
…and 23 more