¡¾Îó²îͨ¸æ¡¿Linux sudo chroot í§Òâ´úÂëÖ´ÐÐÎó²î (CVE-2025-32463)
Ðû²¼Ê±¼ä 2025-07-02Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Linux sudo chroot í§Òâ´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-32463 | ||
Îó²îÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-07-02 |
Îó²îÆÀ·Ö | 9.3 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Sudo£¨Super User Do£©ÊÇLinuxºÍUnixϵͳÖеÄÒ»¿îÏÂÁîÐй¤¾ß£¬ÔÊÐíÊÚȨÓû§ÒÔ³¬µÈÓû§»òÆäËûÓû§µÄÉí·ÝÖ´ÐÐÏÂÁî¡£Ëüͨ¹ýÉèÖÃÎļþ/etc/sudoers½ç˵ÄÄЩÓû§¿ÉÒÔÖ´ÐÐÄÄЩÏÂÁ²¢¼Í¼ÏÂÁîÖ´ÐеÄÈÕÖ¾£¬±ãÓÚÉ󼯡£SudoʵÏÖÁË×îСȨÏÞÔÔò£¬Ê¹µÃÖÎÀíÔ±¿ÉÒÔÊÚÓèÓû§ÓÐÏÞµÄÖÎÀíԱȨÏÞ¶øÎÞÐè¹²ÏírootÃÜÂë¡£ËüÒ²Ö§³ÖÏÂÁîÓÖÃû¡¢Ö÷»úÓÖÃûµÈÎÞаµÄ¹æÔòÉèÖã¬ÆÕ±éÓ¦ÓÃÓÚÇå¾²ÐԽϸߵÄϵͳÖС£
2025Äê7ÔÂ2ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½Linux µÄSudo¹¤¾ß±£´æLinux sudo chroot í§Òâ´úÂëÖ´ÐÐÎó²îCVE-2025-32463ºÍLinux sudo Host OptionÍâµØÌáȨÎó²îCVE-2025-32462£¬CVE-2025-32463ÊÇÒ»¸öí§Òâ´úÂëÖ´ÐÐÎó²î£¬Éæ¼°SudoµÄchroot¹¦Ð§¡£¸Ã¹¦Ð§ÔÊÐí¸ü¸ÄÏÂÁîµÄ¸ùĿ¼£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâµÄ/etc/nsswitch.confÎļþ£¬Ê¹ÓÃSudo¼ÓÔØÓɹ¥»÷Õß¿ØÖƵĹ²Ïí¿â£¬´Ó¶øÖ´ÐÐí§Òâ´úÂ룬µ¼ÖÂrootȨÏÞ±»ÌáÉý¡£¹¥»÷ÕßÄܹ»ÔÚÊÜÏÞÇéÐÎÖÐÖ´Ðб¾Ó¦ÊÜÏÞµÄÏÂÁÔì³ÉÑÏÖØÇ徲Σº¦¡£
CVE-2025-32462ÊÇÒ»¸öÍâµØÈ¨ÏÞÌáÉýÎó²î£¬±£´æÓÚSudoµÄ-h (--host)Ñ¡ÏîÖС£¸ÃÑ¡ÏîÔÊÐíÓû§Éó²éÆäËûÖ÷»úµÄSudoȨÏÞÉèÖá£Ñо¿·¢Ã÷£¬Sudo»á¹ýʧµØ½«Ô¶³ÌÖ÷»úµÄȨÏÞ¹æÔòÓ¦ÓÃÓÚÍâµØÏµÍ³£¬µ¼Ö¹¥»÷ÕßÈÆ¹ýÍâµØÈ¨ÏÞÏÞÖÆ£¬Ö±½Ó»ñµÃrootȨÏÞ¡£´ËÎó²î²»ÐèÒªÖØ´óµÄ¹¥»÷·½·¨¼´¿É±»Ê¹Óá£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
½¨ÒéÁ¬Ã¦Éý¼¶ Sudo ÖÁ 1.9.17p1 »ò¸ü¸ß°æ±¾£¬ÐÞ¸´´ËÎó²î
ÏÂÔØÁ´½Ó£ºhttps://www.sudo.ws/releases/stable/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
?ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£


¾©¹«Íø°²±¸11010802024551ºÅ