Privilege Escalation Vulnerability in Exim Package by SUSE
CVE-2025-53881

6.9MEDIUM

Key Information:

Vendor

Opensuse

Vendor
CVE Published:
2 October 2025

What is CVE-2025-53881?

A vulnerability exists in the Exim package for SUSE Tumbleweed that allows for privilege escalation due to improper handling of UNIX symbolic links in the logrotate configuration. This flaw permits a mail user or group to elevate their privileges to that of the root user, potentially compromising system integrity and security.

Affected Version(s)

Tumbleweed ? < 4.98.2-lp156.248.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matthias Gerstner of SUSE
.
CVE-2025-53881 : Privilege Escalation Vulnerability in Exim Package by SUSE