๐Ÿ” CVE Alert

CVE-2025-2515

HIGH 7.2

Bluechi: privilege escalation in bluechi via unrestricted cross-node systemd dependencies

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node. This issue can lead to privilege escalation, unauthorized service execution, and potential system compromise.

CWE CWE-863
Vendor eclipse foundation
Product bluechi
Published Dec 24, 2025
Last Updated Dec 24, 2025
Stay Ahead of the Next One

Get instant alerts for eclipse foundation bluechi

Be the first to know when new high vulnerabilities affecting eclipse foundation bluechi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Eclipse Foundation / BlueChi
0 < 1.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2025-2515 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2353313 github.com: https://github.com/eclipse-bluechi/bluechi/commit/fe0d28301ce2bd45f0b1d8a98a94efef799fbc73#diff-64140c83db42a8888f346a40de293b80f79ebf7d75ce4137b22567e360bce607 github.com: https://github.com/eclipse-bluechi/bluechi/issues/1069 github.com: https://github.com/eclipse-bluechi/bluechi/pull/1073

Credits

Red Hat would like to thank Thibault Guittet (RedHat) and Todd Cullum (RedHat) for reporting this issue.