
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-53881 is a UNIX Symbolic Link (Symlink) Following vulnerability in the logrotate configuration of the exim package on openSUSE Tumbleweed. It allows a local attacker with mail user/group privileges to escalate to root by exploiting improper symlink resolution during log rotation. The vulnerability affects openSUSE Tumbleweed versions prior to exim 4.98.2-lp156.248.1. It was published on October 2, 2025, and assigned a CVSS v4.0 base score of 6.9 (Medium) (Feedly, EUVD).
The root cause is classified as CWE-61 (UNIX Symbolic Link Following), where the logrotate configuration for the exim mail transfer agent fails to safely resolve symbolic links before accessing log files. During scheduled log rotation (typically run as root), an attacker with mail user/group access can replace a log file or directory with a symlink pointing to an arbitrary file, causing logrotate to operate on that target with root privileges. This is a local privilege escalation requiring low-level initial access (PR:L) with no user interaction needed. The attack pattern maps to CAPEC-27 (Leveraging Race Conditions via Symbolic Links) (Feedly, openSUSE Security).
Successful exploitation allows a local attacker holding mail user/group membership to escalate privileges to root on the affected openSUSE Tumbleweed system. This results in high confidentiality impact (full read access to system files), with low integrity and availability impacts. A compromised root account enables complete system takeover, potential persistence mechanisms, and access to all data on the host (Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-53881. The EPSS score is approximately 0.016% (0.000160), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access with mail user/group privileges, significantly limiting the attacker pool (Feedly).
mail user or group (e.g., via a compromised mail-related service or application)./etc/logrotate.d/exim) and identify the log file paths being rotated./etc/passwd, /etc/shadow, or a root-owned script)./var/log/exim/) pointing to files outside the log directory; unusual modification timestamps on system files like /etc/passwd or /etc/shadow coinciding with logrotate execution times./var/log/syslog or journalctl) showing operations on unexpected file paths; audit log entries (/var/log/audit/audit.log) recording symlink creation by mail-group users in log directories.auditd or inotifywait monitoring on exim log paths.Update the exim package on openSUSE Tumbleweed to version 4.98.2-lp156.248.1 or later, which contains the fixed logrotate configuration. As a workaround prior to patching, administrators can add the su root mail directive and enable nocreate/nolink options in the exim logrotate configuration to prevent symlink following. Restricting write access to exim log directories to only the root user can also reduce exposure (openSUSE Security, SUSE Bugzilla).
The openSUSE security team disclosed this vulnerability as part of a summer security spotlight post published on October 1, 2025. Social media activity was limited, with brief mentions on Mastodon (infosec.exchange and social.circl.lu) shortly after publication. No significant vendor statements beyond the openSUSE advisory or notable researcher commentary have been identified (openSUSE Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."