目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-75092— Leapp 9to10 插件加载权限漏洞

一分钟漏洞结论

影响对象
Red Hat Red Hat Enterprise Linux 8
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

权限提升漏洞:在 提供的 包的 actor 中发现了权限提升漏洞。 在从 RHEL 9 升级到 RHEL 10 的过程中,该 actor 会以 root 身份在 Leapp actor 上下文中直接运行: 这一操作绕过了通常以 身份启动守护进程的标准 MySQL systemd 单元。 攻击路径: 以 OS 身份被攻陷的进程可以向 (该目录由 用户所有)写入: - 一个 version-2 的持久化配置文件( ); - 一个恶意的共享对象(shared object)。 该持久化配置可以将 设置为 ,并设置 (或相

CVSS 7.3 · High
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-75092 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins
来源: CVE Program / CVE List V5
Vulnerability Description
A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql. A process compromised as the mysql OS identity can write a version-2 persisted configuration (mysqld-auto.cnf) and a malicious shared object into /var/lib/mysql (a directory owned by mysql). That persisted map can set plugin_dir to /var/lib/mysql and early_plugin_load (or related loader options such as plugin_load / plugin_load_add) so MySQL loads the attacker-controlled object during configuration validation. Plugin loading can reach dlopen() before MySQL’s runtime-user check and before plugin-symbol validation. When an administrator subsequently runs the documented Leapp preupgrade or upgrade workflow, attacker-controlled code can execute as UID 0 with a full capability set in an unconfined SELinux domain (unconfined_t). The attack does not require write access to the default system plugin path under /usr; redirecting plugin_dir via mysql-owned persisted state is sufficient. Ordinary SQL privileges alone (including highly privileged SQL accounts) are not a sufficient startpoint — OS-level execution as the mysql service identity is required, plus later administrator invocation of Leapp.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
带着不必要的权限执行
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat OpenStack Platform 17.1 - cpe:/a:redhat:openstack:17.1

二、漏洞 CVE-2026-75092 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-75092 的情报信息

登录查看更多情报信息。

CVE-2026-75092 补丁与修复 (1)

CVE-2026-75092 其他参考 (3)

同批安全公告 · Red Hat · 2026-09-15 · 共 3 条

CVE-2026-81303 6.3 MEDIUM hawtio-operator 自定义路由混淆代理人漏洞
CVE-2026-81320 5.5 MEDIUM Hawtio-operator 调试日志泄露TLS私钥

IV. Related Vulnerabilities

V. Comments for CVE-2026-75092

暂无评论


发表评论