CVE-2025-12744Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them directly into a shell command (docker inspect %s) without proper validation. An unprivileged local user can craft a payload that injects shell metacharacters, causing the root-running ABRT process to execute attacker-controlled commands and ultimately gain full root privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-29: 1Technical Details · 2026-04-29: 104-29
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2025-12744 enables local privilege escalation in Fedora 43 and below via ABRT daemon socket manipulation. Exploit chains multiple stages to escape systemd sandbox and gain root access. #DFIR_Radar https://t.co/6XLCLYmlM6

    Post summary

    The tweet discloses details of CVE‑2025‑12744, outlining its impact and exploitation vector, but does not provide a PoC, exploit code, or evidence of active attacks.

    50041975
    1.7K followersView on X

Explore more