CVE-2025-5054 is a local race-condition vulnerability in Canonical apport up to and including version 2.32.0. During crash handling, apport called _check_global_pid_and_forward before consistency_checks. _check_global_pid_and_forward determines whether the crashing process was running in a container and, if so, may forward the core dump accordingly, while consistency_checks attempts to verify that the crashing process has not been replaced. Because this ordering was unsafe, an attacker could exploit PID reuse: after a target process crashed, the attacker could rapidly cause the same PID to be reused by a containerized process. Apport could then incorrectly associate the crash with the replacement containerized process and forward the original core dump to that container. The issue is specifically described as being exploitable via PID reuse by leveraging namespaces, resulting in disclosure of sensitive information contained in the core dump.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
consistency_checks is performed before _check_global_pid_and_forward. In addition, crash forwarding to containers is now restricted: apport only forwards crashes to containers when the kernel supplied a pidfd, or when the crashing process was unprivileged (dump mode == 1).No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.