Another elegant #vulnerability #advisory by @qualys that was published a few months back
Local information disclosure in #apport and #systemd- #coredump
(CVE-2025-5054 and CVE-2025-4598)
https://www.qualys.com/2025/05/29/apport-coredump/apport-coredump.txt
Two information disclosure flaws have been identified in #apport and #systemd-coredump, the core dump handlers in #Ubuntu, #RedHat Enterprise #Linux, and #Fedora, according to the #Qualys Threat Research Unit (TRU).
Tracked as CVE-2025-5054 and CVE-2025-4598, both #vulnerabilities are race condition bugs that could enable a local attacker to obtain access to access sensitive information. Tools like Apport and systemd-coredump are designed to handle crash reporting and core dumps in Linux systems.
https://thehackernews.com/2025/05/new-linux-flaws-allow-password-hash.html
God knows if that'll mean #apport is any more useful next time #Kleopatra crashes.
I live in hope (;*
Why is #apport so crap?
I killed an application because it froze, and apport decided to suggest I report it, I chose not to, and then apport decided that everything else currently running had crashed. None of it had.
Very nearly had to kill apport, it was getting annoying, only it finally decided it had wasted enough of my time and killed itself.