CVE-2025-27591 Details
Description
A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.
A privilege escalation vulnerability exists in the Below service, specifically in versions prior to 0.9.0. The issue arises from the creation of a world-writable directory at /var/log/below, which can allow local unprivileged users to escalate to root privileges. This can be achieved through symlink attacks that manipulate sensitive files, such as /etc/shadow.
Users can update to Below version 0.9.0 or later, which addresses the permission issues by removing the problematic assignments and allowing systemd to manage the log directory safely.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/03/12/1 | CVE | ExploitMailing List |
| https://github.com/facebookincubator/below/commit/da9382e6e3e332fd2c3195e22f34977f83f0f1f3 | [email protected] | Patch |
| https://www.facebook.com/security/advisories/cve-2025-27591 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| facebook below | < 0.9.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 3, 2025 | Initial Analysis | [email protected] |
| Mar 21, 2025 | CVE Modified | CISA-ADP |
| Mar 12, 2025 | CVE Modified | CVE |
| Mar 11, 2025 | New CVE Received | [email protected] |