¡¾·ì϶¹«¸æ¡¿Linux sudo chroot ËÁÒâ´úÂëÖ´Ðзì϶ (CVE-2025-32463)
°ä²¼¹¦·ò 2025-07-02Ò»¡¢·ì϶¸ÅÊö
·ì϶Ãû³Æ | Linux sudo chroot ËÁÒâ´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2025-32463 | ||
·ì϶ÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2025-07-02 |
·ì϶ÆÀ·Ö | 9.3 | ·ì϶µÈ¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ±¾µØ | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Sudo£¨Super User Do£©ÊÇLinuxºÍUnixϵͳÖеÄÒ»¿îºÅÁîÐй¤¾ß£¬£¬£¬ÔÊÐíÊÚȨÓû§ÒÔ³¬µÈÓû§»òÆäËûÓû§µÄÉí·ÝÖ´ÐкÅÁî¡£¡£Ëüͨ¹ýÅäÖÃÎļþ/etc/sudoers½ç˵ÄÄЩÓû§Äܹ»Ö´ÐÐÄÄЩºÅÁ£¬£¬²¢¼Í¼ºÅÁîÖ´ÐеÄÈÕÖ¾£¬£¬£¬±ãÓÚÉ󼯡£¡£SudoʵÏÖÁË×îСȨÏÞ×¼Ôò£¬£¬£¬Ê¹µÃÖÎÀíÔ±Äܹ»ÊÚÓèÓû§ÓÐÏÞµÄÖÎÀíԱȨÏÞ¶øÎÞÐè¹²ÏírootÃÜÂë¡£¡£ËüÒ²Ö§³ÖºÅÁî±ðºÅ¡¢Ö÷»ú±ðºÅµÈ½Ã½ÝµÄ¹æ¶¨ÅäÖ㬣¬£¬¿í·ºÀûÓÃÓÚ°²È«ÐԽϸߵÄϵͳÖС£¡£
2025Äê7ÔÂ2ÈÕ£¬£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½Linux µÄSudo¹¤¾ß´æÔÚLinux sudo chroot ËÁÒâ´úÂëÖ´Ðзì϶CVE-2025-32463ºÍLinux sudo Host Option±¾µØÌáȨ·ì϶CVE-2025-32462£¬£¬£¬CVE-2025-32463ÊÇÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶£¬£¬£¬Éæ¼°SudoµÄchrootÖ°ÄÜ¡£¡£¸ÃÖ°ÄÜÔÊÐí¸ü¸ÄºÅÁîµÄ¸ùĿ¼£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄ/etc/nsswitch.confÎļþ£¬£¬£¬ÀûÓÃSudo¼ÓÔØÓɹ¥»÷Õß½ÚÖÆµÄ¹²Ïí¿â£¬£¬£¬´Ó¶øÖ´ÐÐËÁÒâ´úÂ룬£¬£¬µ¼ÖÂrootȨÏÞ±»ÌáÉý¡£¡£¹¥»÷Õß¿ÉÄÜÔÚÊÜÏÞ»·¾³ÖÐÖ´Ðб¾Ó¦ÊÜÏ޵ĺÅÁ£¬£¬Ôì³ÉÑÏÖØ°²È«·çÏÕ¡£¡£
CVE-2025-32462ÊÇÒ»¸ö±¾µØÈ¨ÏÞÌáÉý·ì϶£¬£¬£¬´æÔÚÓÚSudoµÄ-h (--host)Ñ¡ÏîÖС£¡£¸ÃÑ¡ÏîÔÊÐíÓû§²é¿´ÆäËûÖ÷»úµÄSudoȨÏÞÅäÖᣡ£×êÑз¢ÏÖ£¬£¬£¬Sudo»áÃýÎ󵨽«Ô¶³ÌÖ÷»úµÄȨÏ޹涨ÀûÓÃÓÚ±¾µØÏµÍ³£¬£¬£¬µ¼Ö¹¥»÷ÕßÈÆ¹ý±¾µØÈ¨ÏÞÏÞ¶È£¬£¬£¬Ö±½Ó»ñµÃrootȨÏÞ¡£¡£´Ë·ì϶²»±ØÒª¸´ÔӵĹ¥»÷·½Ê½¼´¿É±»ÀûÓᣡ£
¶þ¡¢Ó°ÏìÁìÓò
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
½¨ÒéÁ¢¼´Éý¼¶ Sudo ÖÁ 1.9.17p1 »ò¸ü¸ß°æ±¾£¬£¬£¬ÐÞ¸´´Ë·ì϶
ÏÂÔØÁ´½Ó£º£º£ºhttps://www.sudo.ws/releases/stable/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£¡£
3.3 ͨÓý¨Òé
?ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ