CVE-2025-2515
Unknown
Unknown - Not Provided
Privilege Escalation via Systemd Unit Override in BlueChi
Publication date: 2025-12-24
Last updated on: 2025-12-24
Assigner: Red Hat, Inc.
Description
Description
A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node. This issue can lead to privilege escalation, unauthorized service execution, and potential system compromise.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| bluechi | bluechi | * |
| eclipse | bluechi | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |