QSearchQSearch

CVE-2015-8325

7.8 HIGH

The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to re...

Published: 2016-05-01 · Last updated: 2026-05-06

Severity and scoring

CVSS
7.8 HIGH
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-264

Affected products

VendorProduct
canonicaldebian_linux, openssh, ubuntu_core
debiandebian_linux, openssh, ubuntu_core
openbsddebian_linux, openssh, ubuntu_core

Description

The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-47337 Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket ... (3.3 LOW)
  • CVE-2026-47336 Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code (3.3 LOW)
  • CVE-2026-47335 Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications (5.5 MEDIUM)
  • CVE-2026-47334 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code (5.5 MEDIUM)
  • CVE-2026-47333 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, l... (7.8 HIGH)

Same CWE

  • CVE-2026-41974 Permission control vulnerability in service notifications (3.6 LOW)
  • CVE-2026-9368 A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16 (7.3 HIGH)
  • CVE-2025-66329 Permission control vulnerability in the window management module (4.0 MEDIUM)
  • CVE-2016-9366 An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series version... (9.8 CRITICAL)
  • CVE-2016-10010 sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local... (7.0 HIGH)