access.redhat.comvdb entry
https://access.redhat.com/security/cve/CVE-2025-2515 CVE-2025-2515
HIGH
Bluechi: privilege escalation in bluechi via unrestricted cross-node systemd dependencies
Record summary
CVE-2025-2515 has a selected CVSS score of 7.2 (high).
Description
A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node. This issue can lead to privilege escalation, unauthorized service execution, and potential system compromise.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 24, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 1.0.0 | affected |
References
6RHBZ#2353313issue tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2353313 github.com
https://github.com/eclipse-bluechi/bluechi/commit/fe0d28301ce2bd45f0b1d8a98a94efef799fbc73 github.com
https://github.com/eclipse-bluechi/bluechi/issues/1069 github.com
https://github.com/eclipse-bluechi/bluechi/pull/1073 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-2515