Vulnerability Description
In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Desktop Provision | 24.04.4 |
Related Weaknesses (CWE)
References
- https://github.com/canonical/ubuntu-desktop-provision/pull/1399Issue TrackingPatch
- https://github.com/canonical/ubuntu-desktop-provision/pull/1400Issue TrackingPatch
FAQ
What is CVE-2025-15480?
CVE-2025-15480 is a vulnerability with a CVSS score of 9.1 (CRITICAL). In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-deskt...
How severe is CVE-2025-15480?
CVE-2025-15480 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-15480?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Desktop Provision.