CVE-2025-2515

high

Description

A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node. This issue can lead to privilege escalation, unauthorized service execution, and potential system compromise.

References

https://github.com/eclipse-bluechi/bluechi/pull/1073

https://github.com/eclipse-bluechi/bluechi/issues/1069

https://github.com/eclipse-bluechi/bluechi/commit/fe0d28301ce2bd45f0b1d8a98a94efef799fbc73#diff-64140c83db42a8888f346a40de293b80f79ebf7d75ce4137b22567e360bce607

https://bugzilla.redhat.com/show_bug.cgi?id=2353313

https://access.redhat.com/security/cve/CVE-2025-2515

Details

Source: Mitre, NVD

Published: 2025-12-24

Updated: 2026-06-25

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:L/AC:L/Au:M/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.2

Vector: CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00018