Vulnerabilities in the Kea DHCP and cyrus-imapd packages allow privilege escalation in the system.

In the configurations of the Kea DHCP server used by various distributions, developed by the ISC consortium as a replacement for the classic ISC DHCP, vulnerabilities have been identified that in some situations allow a local user to execute code with root privileges or overwrite any file in the system:

  • CVE-2025-32801 — allows a local user to gain root privileges on systems where Kea is running under the root user, or to gain full control over the Kea server in systems running Kea under a user with reduced privileges. The attack is carried out through access to the REST API provided by the kea-ctrl-agent service, which by default accepts requests via localhost:8000. In most configurations, the REST API is accessible to all local users of the system without passing authentication.

    Exploitation is carried out by sending the set-config command that allows managing the settings of all Kea services. Among other things, the command can be used to change the "hooks-libraries" parameter, which affects the loading of additional handler libraries. The attacker can achieve the execution of their code in the context of Kea services by substituting their library, the function with the "constructor" attribute of which will be called when opening the library with the dlopen() function. curl -X POST -H "Content-Type: application/json" \ -d '{ "command": "config-set", "arguments": { "Control-agent": {"hooks-libraries": [{"library": "/home/someuser/libexploit.so"}] }}}' \ localhost:8000

  • CVE-2025-32802 — the vulnerability allows the use of the config-write command in the REST API to overwrite any file in the system, as far as the permissions of the user under which Kea is running allow. The attacker can control the written content, but the data is written in JSON format and must include correct Kea settings. However, it cannot be ruled out that this may be sufficient to execute commands with root privileges by manipulating files in the /etc/profile.d directory. curl -X POST -H "Content-Type: application/json" \ -d '{ "command": "config-write", "arguments": { "filename": "/etc/evil.conf" } }' \ localhost:8000

    Erinevalt mainitakse mitmeid kasutusjuhtumeid config-write kĂ€su seadete muutmiseks Kea-s. NĂ€iteks saab logifailide suunata mis tahes faili sĂŒsteemi kohta, korraldada UNIXi soklite teenuste spofingut vĂ”i blokeerida Kea toimimist.

  • CVE-2025-32803 — logid (/var/log/kea*.log) ja failid /var/lib/kea/*.cvs, mis sisaldavad teavet seondumise kohta IP-aadresse (DHCP rent) ja sellega seotud andmed on kergesti loetavad kĂ”ikidele.

Kea kĂ€ivitamine root Ă”igustes on praktiseeritud Arch Linuxi, Gentoo, openSUSE Tumbleweed (kuni 23. maini), FreeBSD, NetBSD (pkgsrc) ja OpenBSD distributsioonides. Debianis, Ubuntus ja Fedoral kĂ€ivitatakse teenus eraldi mitteprivilegeeritud kasutaja all. Gentoo paketiga Kea on saadaval ainult unstable-repositooriumis amd64 arhitektuurile. Ubuntu erinevalt teistest sĂŒsteemidest kĂ€ivitas kea-ctrl-agent teenuse ainult siis, kui juurdepÀÀsu REST API-le oli seadistatud salasĂ”na kaudu. Pakettide uuenduste avaldamist distributsioonide jaoks saab jĂ€lgida lehtedelt: Debian, Ubuntu, RHEL, openSUSE, Fedora, Gentoo, ALT Linux, Arch, FreeBSD, OpenBSD ja NetBSD.

Lisaks vĂ”ib mĂ€rkida haavatavust (CVE-2025-23394), mis ilmneb Cyrus IMAP-serveri paketis, mis on antud openSUSE projekti poolt Tumbleweed ja Factory repositooriumides. See haavatavus vĂ”imaldab kohalikul kasutajal tĂ”sta Ă”igusi cyruselt root-iks. Haavatavusele on antud kriitiline ohu tase (9.8 skaalal 10-st), kuid see on pĂ”hjendamatult kĂ”rge, kuna rĂŒnnakuks on vajalik cyruse Ă”iguste olemasolu, mida saab saada mĂ”ne muu cyrus-imapd haavatavuse Ă€rakasutamise kaudu.

Probleem tuleneb veast sĂŒmboolsete linkide töötlemisel skriptis daily-backup.sh, mis on spetsiifiline SUSE/openSUSE distributsioonide jaoks. Haavatavuse olemus on see, et skript daily-backup.sh kĂ€ivitatakse root Ă”igustes, kuid kirjutab katalooge /var/lib/imap, kus privileegideta kasutaja cyrus saab faile luua. RĂŒnnak seisneb sĂŒmboolse lingi loomises, mis osutab sĂŒsteemifailile (nĂ€iteks vĂ”ib luua sĂŒmboolse lingi /var/lib/imap/mailboxes.txt, mis osutab /etc/shadow). Haavatavus on kĂ”rvaldatud cyrus-imapd paketi versioonis 3.8.4-2.1.

Allikas: opennet.ru

Osta usaldusvÀÀrne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid đŸ”„ Osta usaldusvÀÀrne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid | ProHoster