Spyke

It is an issue in a managed environment such as on corporation or school PCs.

1

The first vulnerability, CVE-2025-5054, affects Ubuntu’s Apport crash reporting system, while the second, CVE-2025-4598, impacts systemd-coredump, the default core dump handler used across Red Hat Enterprise Linux 9 and 10, as well as Fedora distributions.

9

Skimming through the Qualsys report it seems that the attacker would already need access to the device first, to be able to crash the processes and then collect the hashes, so I'd say this vulnerability appears to need chaining with other(s)?

8

You reached the end

Critical Linux Vulnerabilities Expose Password Hashes on Millions of Linux Systems Worldwide | Spyke