https://nvd.nist.gov/vuln/detail/CVE-2025-6020

 

NVD - CVE-2025-6020

CVE-2025-6020 Detail Awaiting Analysis This CVE record has been marked for NVD enrichment efforts. Description A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to e

nvd.nist.gov

 

 

๋ฆฌ๋ˆ…์Šค ์‹œ์Šคํ…œ์˜ ํ•ต์‹ฌ ๋ณด์•ˆ ๋ชจ๋“ˆ์ธ linux-pam์—์„œ ์น˜๋ช…์ ์ธ ์ทจ์•ฝ์ (CVE-2025-6020)์ด ๋ฐœ๊ฒฌ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์€ ๋‚ฎ์€ ๊ถŒํ•œ์„ ๊ฐ€์ง„ ์‚ฌ์šฉ์ž๊ฐ€ root ๊ถŒํ•œ์„ ํš๋“ํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ ์ƒ์Šน(Local Privilege Escalation) ์ด์Šˆ๋กœ ๋ถ„๋ฅ˜๋˜๋ฉฐ, ์ด๋ฏธ ์ฃผ์š” ๋ฐฐํฌํŒ์—์„œ ์˜ํ–ฅ์„ ๋ฐ›๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

 

 

 

 

๐Ÿ“Œ ์ทจ์•ฝ์  ๊ฐœ์š”

 

 

  • ID: CVE-2025-6020
  • ์˜ํ–ฅ ๋ชจ๋“ˆ: pam_namespace (linux-pam)
  • ์‹ฌ๊ฐ๋„: 7.8 (CVSS 3.1 ๊ธฐ์ค€ - High)
  • ๊ณต๊ฒฉ ๊ฒฝ๋กœ: ๋กœ์ปฌ ์‚ฌ์šฉ์ž
  • ์ฃผ์š” ๋ฌธ์ œ์ : ์‚ฌ์šฉ์ž ์ œ์–ด ๊ฒฝ๋กœ(User-controlled paths)๋ฅผ ์ ์ ˆํžˆ ๊ฒ€์ฆํ•˜์ง€ ์•Š์•„ ์‹ฌ๋ณผ๋ฆญ ๋งํฌ(Symlink) ๋˜๋Š” ๊ฒฝํ•ฉ ์กฐ๊ฑด(Race Condition)์„ ํ†ตํ•ด root ๊ถŒํ•œ ํƒˆ์ทจ ๊ฐ€๋Šฅ

 

 

 

 

 

๐Ÿ–ฅ๏ธ ์˜ํ–ฅ ๋ฐ›๋Š” ์‹œ์Šคํ…œ

 

 

  • linux-pam ๋ฒ„์ „ 1.7.0 ์ดํ•˜ ์‚ฌ์šฉ ์‹œ์Šคํ…œ
  • ์ฃผ์š” ์˜ํ–ฅ ๋ฐฐํฌํŒ:
  •  

 

 

 

 

 

๐Ÿ”ง ๋Œ€์‘ ๋ฐฉ์•ˆ

 

 

 

1. ํŒจ์น˜ ์ ์šฉ

 

 

  • linux-pam 1.7.1 ์ด์ƒ์œผ๋กœ ์ฆ‰์‹œ ์—…๊ทธ๋ ˆ์ด๋“œ ํ•„์š”
  • ๊ฐ ๋ฐฐํฌํŒ๋ณ„ ๋ณด์•ˆ ํŒจ์น˜ ํ™•์ธ ๋ฐ ์—…๋ฐ์ดํŠธ ์‹คํ–‰

 

 

 

2. ์ž„์‹œ ๋Œ€์‘

 

 

  • pam_namespace ๋ชจ๋“ˆ ๋น„ํ™œ์„ฑํ™”
  • namespace.init ๋‚ด ์‚ฌ์šฉ์ž ์ œ์–ด ๊ฒฝ๋กœ ์ œ๊ฑฐ
  • ๊ด€๋ จ ์‹œ์Šคํ…œ ๋ฐ๋ชฌ(์˜ˆ: udisks)์˜ Polkit ๊ถŒํ•œ ๊ทœ์น™ ๊ฐ•ํ™”

 

 

 

 

 

โš ๏ธ ์‹œ์Šคํ…œ ๋ณด์•ˆ ์ ๊ฒ€ ์ฒดํฌ๋ฆฌ์ŠคํŠธ

 

 

  • ํ˜„์žฌ ์šด์˜ ์ค‘์ธ linux-pam ๋ฒ„์ „ ํ™•์ธ
  • root ์ด์™ธ ์‚ฌ์šฉ์ž ๊ณ„์ •์˜ sudoers ๊ถŒํ•œ ์ ๊ฒ€
  • ๋กœ๊ทธ์ธ/์ ‘๊ทผ ๋กœ๊ทธ ์ด์ƒ ํ™œ๋™ ํƒ์ง€
  • /etc/security/namespace.conf ์„ค์ • ๊ฒ€ํ† 
  • ์ž๋™ํ™”๋œ ์—…๋ฐ์ดํŠธ ์Šค์ผ€์ค„ ํ™•์ธ

 

 

 

 

 

๐Ÿ’ฌ FAQ

 

 

 

Q1. ์ด ์ทจ์•ฝ์ ์ด ์™œ ์œ„ํ—˜ํ•œ๊ฐ€์š”?

 

 

A. ๋กœ์ปฌ ์‚ฌ์šฉ์ž ๊ถŒํ•œ๋งŒ์œผ๋กœ๋„ root ํƒˆ์ทจ๊ฐ€ ๊ฐ€๋Šฅํ•˜๋ฏ€๋กœ, ๋ณด์•ˆ์— ์น˜๋ช…์ ์ธ ์˜ํ–ฅ์„ ๋ฏธ์น  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

 

 

Q2. ๋ฐ˜๋“œ์‹œ ํŒจ์น˜๊ฐ€ ํ•„์š”ํ•œ๊ฐ€์š”?

 

 

A. ๋„ค, ํŒจ์น˜ ์—†์ด ๋ฐฉ์น˜ ์‹œ ์‹œ์Šคํ…œ ์ „์ฒด ์ œ์–ด๊ถŒ์„ ํƒˆ์ทจ๋‹นํ•  ์œ„ํ—˜์ด ์žˆ์Šต๋‹ˆ๋‹ค.

 

 

Q3. ์ผ๋ฐ˜ ์‚ฌ์šฉ์ž๋Š” ์˜ํ–ฅ์ด ์—†๋‚˜์š”?

 

 

A. ์ทจ์•ฝํ•œ ์‹œ์Šคํ…œ์— ์ ‘๊ทผ ๊ถŒํ•œ์ด ์žˆ๋Š” **๋ชจ๋“  ์‚ฌ์šฉ์ž(์‹ฌ์ง€์–ด ๊ฐœ๋ฐœ์šฉ ๋กœ์ปฌ ๊ณ„์ • ํฌํ•จ)**๊ฐ€ ๊ณต๊ฒฉ์ž๊ฐ€ ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

 

 

 

 

๐Ÿท๏ธ ๊ด€๋ จ ํƒœ๊ทธ

 

 

#CVE20256020 #linuxpam #๋ฆฌ๋ˆ…์Šค๋ณด์•ˆ #๋ฃจํŠธ๊ถŒํ•œํƒˆ์ทจ #์ทจ์•ฝ์ ๋ถ„์„ #๋ณด์•ˆํŒจ์น˜ #๊ถŒํ•œ์ƒ์Šน #ubuntu #rhel #suse #์‹œ์Šคํ…œ๋ณด์•ˆ

 

 

 

๐Ÿ“ข ๋ณด์•ˆ ์ทจ์•ฝ์ ์€ ‘์•Œ๊ณ ๋„ ๋ฐฉ์น˜’๊ฐ€ ๊ฐ€์žฅ ์œ„ํ—˜ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ‘‰ Find2Everything, ์ •๋ณด์˜ ๋ชจ๋“  ๊ฒƒ์—์„œ ์‹ค์‹œ๊ฐ„ ๋ณด์•ˆ ์ด์Šˆ๋ฅผ ํ™•์ธํ•˜์„ธ์š”!

 

+ Recent posts