A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node. This issue can lead to privilege escalation, unauthorized service execution, and potential system compromise.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node. This issue can lead to privilege escalation, unauthorized service execution, and potential system compromise. | |
| Title | Bluechi: privilege escalation in bluechi via unrestricted cross-node systemd dependencies | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-12-24T16:48:19.891Z
Reserved: 2025-03-19T07:36:36.135Z
Link: CVE-2025-2515
Updated: 2025-12-24T16:48:14.309Z
Status : Received
Published: 2025-12-24T17:15:47.293
Modified: 2025-12-24T17:15:47.293
Link: CVE-2025-2515
No data.
OpenCVE Enrichment
No data.