Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2025-34034: Linux permits attackers to gain elevated privileges

CVE-2025-34034 · published 1 day ago
Summary

The Linux package used in Ubuntu 22.04 can let an attacker increase their access rights on the system. This weakness has been fixed in several newer releases of the Linux and related packages. Apply the latest updates for the Linux package (and any related rootio-linux components) as soon as possible.

What to do
  • Update canonical linux to version 5.15.0-191.201.aikido.115.
  • Update canonical rootio-linux to version 5.15.0-191.201.aikido.115.
  • Update linux to version 5.15.0-198.208.aikido.116.
  • Update rootio-linux to version 5.15.0-198.208.aikido.116.
Affected software
Ecosystem VendorProductAffected versions
Root:Ubuntu:22.04 canonical linux < 5.15.0-191.201.aikido.115
Fix: upgrade to 5.15.0-191.201.aikido.115
Root:Ubuntu:22.04 canonical rootio-linux < 5.15.0-191.201.aikido.115
Fix: upgrade to 5.15.0-191.201.aikido.115
– 5vtechnologies blue_angel_software_suite All versions
cpe:2.3:a:5vtechnologies:blue_angel_software_suite:*:*:*:*:*:*:*:*
Root:Ubuntu:22.04 – linux < 5.15.0-198.208.aikido.116
Fix: upgrade to 5.15.0-198.208.aikido.116
Root:Ubuntu:22.04 – rootio-linux < 5.15.0-198.208.aikido.116
Fix: upgrade to 5.15.0-198.208.aikido.116
Original advisory text
CVE-2025-34034 in linux - Patched by Root
Root has patched CVE-2025-34034 in the linux package for Root:Ubuntu:22.04. Multiple fixed versions available.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published9 Oct 2026
Updated9 Oct 2026
First seen5 Sep 2026
Sources
CVE-2025-34034 · NVD
Track software like this
Free during beta