¡¾Îó²îͨ¸æ¡¿Linux sudo chroot í§Òâ´úÂëÖ´ÐÐÎó²î (CVE-2025-32463)
Ðû²¼Ê±¼ä 2025-07-02Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Linux sudo chroot í§Òâ´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-32463 | ||
Îó²îÀàÐÍ | ´úÂëÖ´ÐÐ | ·¢Ã÷ʱ¼ä | 2025-07-02 |
Îó²îÆÀ·Ö | 9.3 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Sudo£¨Super User Do£©ÊÇLinuxºÍUnixϵͳÖеÄÒ»¿îÏÂÁîÐй¤¾ß£¬£¬£¬£¬ÔÊÐíÊÚȨÓû§ÒÔ³¬µÈÓû§»òÆäËûÓû§µÄÉí·ÝÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£Ëüͨ¹ýÉèÖÃÎļþ/etc/sudoers½ç˵ÄÄЩÓû§¿ÉÒÔÖ´ÐÐÄÄЩÏÂÁ£¬£¬£¬²¢¼Í¼ÏÂÁîÖ´ÐеÄÈÕÖ¾£¬£¬£¬£¬±ãÓÚÉ󼯡£¡£¡£¡£¡£¡£SudoʵÏÖÁË×îСȨÏÞÔÔò£¬£¬£¬£¬Ê¹µÃÖÎÀíÔ±¿ÉÒÔÊÚÓèÓû§ÓÐÏÞµÄÖÎÀíԱȨÏÞ¶øÎÞÐè¹²ÏírootÃÜÂë¡£¡£¡£¡£¡£¡£ËüÒ²Ö§³ÖÏÂÁîÓÖÃû¡¢Ö÷»úÓÖÃûµÈÎÞаµÄ¹æÔòÉèÖ㬣¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚÇå¾²ÐԽϸߵÄϵͳÖС£¡£¡£¡£¡£¡£
2025Äê7ÔÂ2ÈÕ£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½Linux µÄSudo¹¤¾ß±£´æLinux sudo chroot í§Òâ´úÂëÖ´ÐÐÎó²îCVE-2025-32463ºÍLinux sudo Host OptionÍâµØÌáȨÎó²îCVE-2025-32462£¬£¬£¬£¬CVE-2025-32463ÊÇÒ»¸öí§Òâ´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬Éæ¼°SudoµÄchroot¹¦Ð§¡£¡£¡£¡£¡£¡£¸Ã¹¦Ð§ÔÊÐí¸ü¸ÄÏÂÁîµÄ¸ùĿ¼£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâµÄ/etc/nsswitch.confÎļþ£¬£¬£¬£¬Ê¹ÓÃSudo¼ÓÔØÓɹ¥»÷Õß¿ØÖƵĹ²Ïí¿â£¬£¬£¬£¬´Ó¶øÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬µ¼ÖÂrootȨÏÞ±»ÌáÉý¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÔÚÊÜÏÞÇéÐÎÖÐÖ´Ðб¾Ó¦ÊÜÏÞµÄÏÂÁ£¬£¬£¬Ôì³ÉÑÏÖØÇ徲Σº¦¡£¡£¡£¡£¡£¡£
CVE-2025-32462ÊÇÒ»¸öÍâµØÈ¨ÏÞÌáÉýÎó²î£¬£¬£¬£¬±£´æÓÚSudoµÄ-h (--host)Ñ¡ÏîÖС£¡£¡£¡£¡£¡£¸ÃÑ¡ÏîÔÊÐíÓû§Éó²éÆäËûÖ÷»úµÄSudoȨÏÞÉèÖᣡ£¡£¡£¡£¡£Ñо¿·¢Ã÷£¬£¬£¬£¬Sudo»á¹ýʧµØ½«Ô¶³ÌÖ÷»úµÄȨÏÞ¹æÔòÓ¦ÓÃÓÚÍâµØÏµÍ³£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÈÆ¹ýÍâµØÈ¨ÏÞÏÞÖÆ£¬£¬£¬£¬Ö±½Ó»ñµÃrootȨÏÞ¡£¡£¡£¡£¡£¡£´ËÎó²î²»ÐèÒªÖØ´óµÄ¹¥»÷·½·¨¼´¿É±»Ê¹Óᣡ£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
½¨ÒéÁ¬Ã¦Éý¼¶ Sudo ÖÁ 1.9.17p1 »ò¸ü¸ß°æ±¾£¬£¬£¬£¬ÐÞ¸´´ËÎó²î
ÏÂÔØÁ´½Ó£ºhttps://www.sudo.ws/releases/stable/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
?ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ