CVE-2025-67858
Description
A flaw was found in Foomuuri. A local user can exploit this vulnerability by manipulating the JSON configuration passed to nft. This improper neutralization of argument delimiters can lead to the integrity loss of the firewall configuration or other unspecified impacts.
Statement
This vulnerability is rated Important for Red Hat's Community Projects because a local user can exploit an improper neutralization of argument delimiters in Foomuuri. This flaw allows manipulation of the JSON configuration passed to nft, leading to integrity loss of the firewall configuration. This could result in unauthorized network access or other unspecified impacts on affected systems running Foomuuri.
Mitigation
To mitigate this vulnerability, if the Foomuuri package is not essential for system operation, consider removing it. For systems where Foomuuri is required, ensure that only trusted administrators have local access, as exploitation requires local interaction to manipulate firewall configurations.
Understanding the Weakness (CWE)
Confidentiality,Integrity,Availability,Other
Technical Impact: Execute Unauthorized Code or Commands; Alter Execution Logic; Read Application Data; Modify Application Data
An attacker could include arguments that allow unintended commands or code to be executed, allow sensitive data to be read or modified or could cause other unintended behavior.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.