CVE-2025-2515

7.2

Eclipse Foundation · BlueChi

BlueChi, a multi-node systemd service controller, contains an authorization flaw that allows users with root privileges on a managed node to perform unauthorized actions on the host node.

Executive summary

The Eclipse Foundation BlueChi service controller contains an authorization vulnerability that allows an attacker with root access on a managed node to escalate privileges and compromise the host system.

Vulnerability

The software suffers from an incorrect authorization flaw (CWE-863) where a user with root privileges on a managed node (qm) can create or override systemd service unit files on the host node. This requires the attacker to already possess high privileges on a subordinate node to trigger the escalation.

Business impact

Successful exploitation leads to privilege escalation, unauthorized service execution, and potential full system compromise. With a CVSS score of 7.2, this vulnerability represents a high risk to organizational security, particularly in multi-node environments where lateral movement or host-level control is critical to infrastructure integrity.

Remediation

Immediate Action: Update the Eclipse Foundation BlueChi software to version 1.0.0 or later to apply the necessary authorization checks.

Proactive Monitoring: Monitor system logs for unexpected modifications to systemd unit files or service configurations on host nodes.

Compensating Controls: Restrict access to managed nodes to highly trusted personnel and implement strict network segmentation between managed nodes and the host controller to limit the reach of a compromised component.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for complete system compromise within a multi-node deployment, organizations must prioritize patching BlueChi to version 1.0.0. Ensure that all nodes are accounted for in the update cycle to prevent unauthorized cross-node configuration changes that could lead to host-level exploitation.

More Eclipse Foundation CVEs

Sources

Originally found and disclosed by Red Hat would like to thank Thibault Guittet (RedHat) and Todd Cullum (RedHat) for reporting this issue., per the CVE Program record.