8.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them directly into a shell command (docker inspect %s) without proper validation. An unprivileged local user can craft a payload that injects shell metacharacters, causing the root-running ABRT process to execute attacker-controlled commands and ultimately gain full root privileges.
AI Analysis
Command injection vulnerability in ABRT daemon allowing local privilege escalation
Basic Information
ID
CVE-2025-12744
Source
fedora
Published
Dec 3, 2025 at 08:33
Affected Product
Vendor
Red Hat
Product
abrt
Affected Versions
0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Red Hat
Product
ABRT
Version
unknown