CVE-2025-67858

Description

A flaw was found in Foomuuri. A local user can exploit this vulnerability by manipulating the JSON configuration passed to nft. This improper neutralization of argument delimiters can lead to the integrity loss of the firewall configuration or other unspecified impacts.

Statement

This vulnerability is rated Important for Red Hat's Community Projects because a local user can exploit an improper neutralization of argument delimiters in Foomuuri. This flaw allows manipulation of the JSON configuration passed to nft, leading to integrity loss of the firewall configuration. This could result in unauthorized network access or other unspecified impacts on affected systems running Foomuuri.

Mitigation

To mitigate this vulnerability, if the Foomuuri package is not essential for system operation, consider removing it. For systems where Foomuuri is required, ensure that only trusted administrators have local access, as exploitation requires local interaction to manipulate firewall configurations.

Understanding the Weakness (CWE)

Confidentiality,Integrity,Availability,Other

Technical Impact: Execute Unauthorized Code or Commands; Alter Execution Logic; Read Application Data; Modify Application Data

An attacker could include arguments that allow unintended commands or code to be executed, allow sensitive data to be read or modified or could cause other unintended behavior.

Frequently Asked Questions

Want to get errata notifications? Sign up here.