Логотип exploitDog
bind:CVE-2025-27512
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-27512

Количество 3

Количество 3

nvd логотип

CVE-2025-27512

11 месяцев назад

Zincati is an auto-update agent for Fedora CoreOS hosts. Zincati ships a polkit rule which allows the `zincati` system user to use the actions `org.projectatomic.rpmostree1.deploy` to deploy updates to the system and `org.projectatomic.rpmostree1.finalize-deployment` to reboot the system into the deployed update. Since Zincati v0.0.24, this polkit rule contains a logic error which broadens access of those polkit actions to any unprivileged user rather than just the `zincati` system user. In practice, this means that any unprivileged user with access to the system D-Bus socket is able to deploy older Fedora CoreOS versions (which may have other known vulnerabilities). Note that rpm-ostree enforces that the selected version must be from the same branch the system is currently on so this cannot directly be used to deploy an attacker-controlled update payload. This primarily impacts users running untrusted workloads with access to the system D-Bus socket. Note that in general, untrusted wo

EPSS: Низкий
github логотип

GHSA-w6fv-6gcc-x825

11 месяцев назад

Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods

EPSS: Низкий
fstec логотип

BDU:2026-00116

11 месяцев назад

Уязвимость агент автоматического обновления Zincati, связанная с логической ошибкой приоритета операторов, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-27512

Zincati is an auto-update agent for Fedora CoreOS hosts. Zincati ships a polkit rule which allows the `zincati` system user to use the actions `org.projectatomic.rpmostree1.deploy` to deploy updates to the system and `org.projectatomic.rpmostree1.finalize-deployment` to reboot the system into the deployed update. Since Zincati v0.0.24, this polkit rule contains a logic error which broadens access of those polkit actions to any unprivileged user rather than just the `zincati` system user. In practice, this means that any unprivileged user with access to the system D-Bus socket is able to deploy older Fedora CoreOS versions (which may have other known vulnerabilities). Note that rpm-ostree enforces that the selected version must be from the same branch the system is currently on so this cannot directly be used to deploy an attacker-controlled update payload. This primarily impacts users running untrusted workloads with access to the system D-Bus socket. Note that in general, untrusted wo

0%
Низкий
11 месяцев назад
github логотип
GHSA-w6fv-6gcc-x825

Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods

0%
Низкий
11 месяцев назад
fstec логотип
BDU:2026-00116

Уязвимость агент автоматического обновления Zincati, связанная с логической ошибкой приоритета операторов, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 3.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу