CVE-2025-32801

Description

A flaw was found in the Kea package, where an unprivileged user can instruct Kea to load a hook library from any arbitrary local file. This hook can then be executed using the same privileges that Kea runs under. This vulnerability allows an attacker with access to a local, unprivileged account to introduce a malicious local hook library, which Kea will execute, achieving arbitrary code execution and privilege escalation.

Statement

This vulnerability is rated as an Important severity because the vulnerability was found in the configuration and API directives related to hook library loading, it is a local privilege escalation flaw triggered when an attacker with local unprivileged access instructs Kea to load a malicious hook library, which is possible if the API entry points are unsecured or control sockets are in insecure paths. This leads to arbitrary code execution enabling an attacker to gain unauthorized access to sensitive data, alter critical system configurations, and disrupt service availability.

Mitigation

This vulnerability can be mitigated via one of the two following alternatives:

1) Disable the Kea API entirely by disabling the kea-ctrl-agent and removing any control-socket stanzas from the Kea configuration files.

2) Configure the API to require authentication for the kea-ctrl-agent and configuring all "control-socket" stanzes to use a directory restricted to trusted users.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.8N/A7.8
Attack VectorLocalN/ALocal
Attack ComplexityLowN/ALow
Privileges RequiredLowN/ALow
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityHighN/AHigh
Integrity ImpactHighN/AHigh
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

cve.org: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Understanding the Weakness (CWE)

Access Control

Technical Impact: Gain Privileges or Assume Identity

A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.

Frequently Asked Questions

Want to get errata notifications? Sign up here.