CVE-2025-1390Patch

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-23); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-23: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 103-2304-15
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-231
Patch1
2026-04-151
Disclosure1
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔐 Critical security update for the #Ubuntu community! USN-8114-1 addresses CVE-2025-1390, a privilege escalation flaw in the gvfs package. Read more: 👉 https://tinyurl.com/mupkdd5p #Security https://t.co/KFB1GCuQut

    Post summary

    Ubuntu issues a critical patch for CVE‑2025‑1390, a privilege‑escalation flaw in gvfs.

    00010124
    1.5K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2025-1390: Schneider Electric Modicon M241, M251, M262 DoS Vulnerability — … "CISA has released ICSA-26-078-01, detailing a significant vulnerability (CVE-2025-1390)…" 🔗 https://securityarsenal.com/blog/cve-2025-1390-schneider-electric-modicon-m241-m251-m262-dos-vulnerability-detection-and-hardening-guide #CyberSecurity #ThreatIntel #soc #threatintel #managedsoc

    Post summary

    The tweet announces CVE‑2025‑1390—a DoS vulnerability in Schneider Electric Modicon devices—while referencing a CISA KEV advisory, but it offers no PoC, exploit, patch, or detailed technical information.

    00000173
    10 followersView on X

Explore more