A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node. This issue can lead to privilege escalation, unauthorized service execution, and potential system compromise.
History

Wed, 24 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node. This issue can lead to privilege escalation, unauthorized service execution, and potential system compromise.
Title Bluechi: privilege escalation in bluechi via unrestricted cross-node systemd dependencies
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-12-24T16:48:19.891Z

Reserved: 2025-03-19T07:36:36.135Z

Link: CVE-2025-2515

cve-icon Vulnrichment

Updated: 2025-12-24T16:48:14.309Z

cve-icon NVD

Status : Received

Published: 2025-12-24T17:15:47.293

Modified: 2025-12-24T17:15:47.293

Link: CVE-2025-2515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.