CVE-2015-8325
7.8 HIGHThe do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to re...
Published: 2016-05-01 · Last updated: 2026-05-06
Severity and scoring
- CVSS
- 7.8 HIGH
- Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-264
Affected products
| Vendor | Product |
|---|---|
| canonical | debian_linux, openssh, ubuntu_core |
| debian | debian_linux, openssh, ubuntu_core |
| openbsd | debian_linux, openssh, ubuntu_core |
Description
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2015-8325
- [Other]http://rhn.redhat.com/errata/RHSA-2016-2588.html
- [Other]http://rhn.redhat.com/errata/RHSA-2017-0641.html
- [Other]http://www.debian.org/security/2016/dsa-3550
- [Other]http://www.securityfocus.com/bid/86187
- [Other]http://www.securitytracker.com/id/1036487
- [Other]https://anongit.mindrot.org/openssh.git/commit/?id=85bdcd7c92fe7ff133bbc4e10a65c91810f88755
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=1328012
- [Other]https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- [Other]https://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-8325.html
- [Other]https://security-tracker.debian.org/tracker/CVE-2015-8325
- [Other]https://security.gentoo.org/glsa/201612-18
- [Other]https://security.netapp.com/advisory/ntap-20180628-0001/
- [Other]http://rhn.redhat.com/errata/RHSA-2016-2588.html
- [Other]http://rhn.redhat.com/errata/RHSA-2017-0641.html
- [Other]http://www.debian.org/security/2016/dsa-3550
- [Other]http://www.securityfocus.com/bid/86187
- [Other]http://www.securitytracker.com/id/1036487
- [Other]https://anongit.mindrot.org/openssh.git/commit/?id=85bdcd7c92fe7ff133bbc4e10a65c91810f88755
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=1328012
- [Other]https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- [Other]https://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-8325.html
- [Other]https://security-tracker.debian.org/tracker/CVE-2015-8325
- [Other]https://security.gentoo.org/glsa/201612-18
- [Other]https://security.netapp.com/advisory/ntap-20180628-0001/
Related CVEs
Same vendor
- CVE-2026-47337 — Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket ... (3.3 LOW)
- CVE-2026-47336 — Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code (3.3 LOW)
- CVE-2026-47335 — Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications (5.5 MEDIUM)
- CVE-2026-47334 — Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code (5.5 MEDIUM)
- CVE-2026-47333 — Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, l... (7.8 HIGH)
Same CWE
- CVE-2026-41974 — Permission control vulnerability in service notifications (3.6 LOW)
- CVE-2026-9368 — A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16 (7.3 HIGH)
- CVE-2025-66329 — Permission control vulnerability in the window management module (4.0 MEDIUM)
- CVE-2016-9366 — An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series version... (9.8 CRITICAL)
- CVE-2016-10010 — sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local... (7.0 HIGH)