¡¾·ì϶¹«¸æ¡¿Linux sudo chroot ËÁÒâ´úÂëÖ´Ðзì϶ (CVE-2025-32463)
°ä²¼¹¦·ò 2025-07-02Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Linux sudo chroot ËÁÒâ´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2025-32463 | ||
·ì϶ÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-07-02 |
·ì϶ÆÀ·Ö | 9.3 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ±¾µØ | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Sudo£¨Super User Do£©ÊÇLinuxºÍUnixϵͳÖеÄÒ»¿îºÅÁîÐй¤¾ß£¬ÔÊÐíÊÚȨÓû§ÒÔ³¬µÈÓû§»òÆäËûÓû§µÄÉí·ÝÖ´ÐкÅÁî¡£Ëüͨ¹ýÅäÖÃÎļþ/etc/sudoers½ç˵ÄÄЩÓû§Äܹ»Ö´ÐÐÄÄЩºÅÁ²¢¼Í¼ºÅÁîÖ´ÐеÄÈÕÖ¾£¬±ãÓÚÉ󼯡£SudoʵÏÖÁË×îÓ×ȨÏÞ×¼Ôò£¬Ê¹µÃÖÎÀíÔ±Äܹ»ÊÚÓèÓû§ÓÐÏÞµÄÖÎÀíԱȨÏÞ¶øÎÞÐè¹²ÏírootÃÜÂë¡£ËüÒ²Ö§³ÖºÅÁî±ðºÅ¡¢Ö÷»ú±ðºÅµÈ½Ã½ÝµÄ¹æ¶¨ÅäÖã¬¿í·ºÀûÓÃÓÚ°²È«ÐԽϸߵÄϵͳÖС£
2025Äê7ÔÂ2ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Linux µÄSudo¹¤¾ß´æÔÚLinux sudo chroot ËÁÒâ´úÂëÖ´Ðзì϶CVE-2025-32463ºÍLinux sudo Host Option±¾µØÌáȨ·ì϶CVE-2025-32462£¬CVE-2025-32463ÊÇÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶£¬Éæ¼°SudoµÄchrootÖ°ÄÜ¡£¸ÃÖ°ÄÜÔÊÐí¸ü¸ÄºÅÁîµÄ¸ùĿ¼£¬¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄ/etc/nsswitch.confÎļþ£¬ÀûÓÃSudo¼ÓÔØÓɹ¥»÷Õß½ÚÔìµÄ¹²Ïí¿â£¬´Ó¶øÖ´ÐÐËÁÒâ´úÂ룬µ¼ÖÂrootȨÏÞ±»ÌáÉý¡£¹¥»÷Õß¿ÉÄÜÔÚÊÜÏÞ»·¾³ÖÐÖ´Ðб¾Ó¦ÊÜÏ޵ĺÅÁÔì³ÉÑϳÁ°²È«·çÏÕ¡£
CVE-2025-32462ÊÇÒ»¸ö±¾µØÈ¨ÏÞÌáÉý·ì϶£¬´æÔÚÓÚSudoµÄ-h (--host)Ñ¡ÏîÖС£¸ÃÑ¡ÏîÔÊÐíÓû§²é¿´ÆäËûÖ÷»úµÄSudoȨÏÞÅäÖá£×êÑз¢ÏÖ£¬Sudo»áÃýÎ󵨽«Ô¶³ÌÖ÷»úµÄȨÏ޹涨ÀûÓÃÓÚ±¾µØÏµÍ³£¬µ¼Ö¹¥»÷ÕßÈÆ¹ý±¾µØÈ¨ÏÞÏÞ¶È£¬Ö±½Ó»ñµÃrootȨÏÞ¡£´Ë·ì϶²»±ØÒª¸´ÔӵĹ¥»÷·½Ê½¼´¿É±»ÀûÓá£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
½¨Òéµ±¼´Éý¼¶ Sudo ÖÁ 1.9.17p1 »ò¸ü¸ß°æ±¾£¬½¨¸´´Ë·ì϶
ÏÂÔØÁ´½Ó£ºhttps://www.sudo.ws/releases/stable/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


¾©¹«Íø°²±¸11010802024551ºÅ