CVE-2025-67858
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-67858 is an Improper Neutralization of Argument Delimiters (CWE-88) vulnerability in Foomuuri, a firewall management tool, that allows attackers to manipulate the JSON configuration passed to the nft (nftables) command-line utility. Successful exploitation can lead to integrity loss of the firewall configuration or further unspecified impact. The vulnerability affects all Foomuuri versions prior to 0.31. It was disclosed on January 8, 2026, with SUSE as the assigning CNA. The CVSS v4.0 base score is 7.0 (High), assigned by SUSE (Red Hat Advisory, SUSE Bugzilla).

Technical details

The root cause is improper neutralization of argument delimiters (CWE-88) when Foomuuri processes JSON configuration data and passes it to the nft command. An attacker can craft malicious JSON input containing argument delimiters that are not properly sanitized, causing nft to interpret injected arguments as legitimate command parameters. The attack vector is local (AV:L), requires no privileges (PR:N), no user interaction (UI:N), and has no special attack requirements, making it straightforward to exploit for any local user who can influence the JSON configuration. The OpenSUSE security team published a technical advisory describing the issue in the context of missing D-Bus authorization controls in Foomuuri (OpenSUSE Security, oss-sec).

Impact

Successful exploitation primarily impacts the integrity of the firewall configuration (rated HIGH integrity impact), potentially allowing an attacker to weaken or disable firewall rules, enabling unauthorized network access or bypassing security controls. There is also a low-level confidentiality impact (e.g., reading configuration data) and low availability impact. Because firewall integrity is compromised, exploitation could serve as a stepping stone for further attacks, including lateral movement within a network or exposure of otherwise protected services (Red Hat Advisory, OpenSUSE Security).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.022% (0.000220), indicating a very low probability of exploitation in the near term. Detection plugins have been published by Tenable Nessus (plugin IDs 282528 and 291268), enabling automated scanning for vulnerable systems (Red Hat Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify systems running Foomuuri versions prior to 0.31 on Linux distributions (e.g., openSUSE, Fedora, Debian, Ubuntu). Check installed package versions using package managers (rpm -q foomuuri or dpkg -l foomuuri).
  2. Access the configuration interface: As a local user with access to Foomuuri's D-Bus interface or configuration files, prepare a malicious JSON configuration payload containing crafted argument delimiters (e.g., injecting extra nft arguments via unsanitized JSON fields).
  3. Inject malicious arguments: Submit the crafted JSON configuration to Foomuuri (e.g., via D-Bus call or configuration file manipulation), causing Foomuuri to pass the injected arguments to the nft command without proper sanitization.
  4. Manipulate firewall rules: The injected nft arguments execute with the privileges of the Foomuuri service, allowing the attacker to add, remove, or modify firewall rules — for example, opening ports, disabling filtering chains, or flushing rulesets.
  5. Achieve objective: With firewall rules compromised, the attacker can enable access to previously blocked services, facilitate lateral movement, or set up persistent backdoor network access (OpenSUSE Security, oss-sec).

Indicators of compromise

  • Logs: Unexpected nft command invocations in system logs (/var/log/syslog, journalctl) with unusual or extra arguments not matching normal Foomuuri operation; D-Bus activity logs showing unauthorized calls to Foomuuri's D-Bus interface.
  • File System: Unexpected modifications to Foomuuri JSON configuration files (check file modification timestamps); changes to nftables ruleset files in /etc/nftables.conf or related directories.
  • Network: Sudden appearance of new open ports or disappearance of previously enforced firewall rules detectable via nft list ruleset; unexpected inbound or outbound connections to previously blocked addresses.
  • Process: Unusual nft process invocations spawned by the Foomuuri service with anomalous argument strings visible in process listings (ps aux | grep nft) (OpenSUSE Security).

Mitigation and workarounds

The primary remediation is to upgrade Foomuuri to version 0.31 or later, which addresses this argument injection vulnerability. If immediate patching is not possible, restrict local access to systems running vulnerable Foomuuri versions, limit D-Bus access to the Foomuuri service to trusted users only, and monitor firewall configuration files for unauthorized modifications. Implement input validation and sanitization for any JSON configuration data passed to nft. Patches have been distributed for Debian (DSA-6095-1), Fedora 42, and Ubuntu (USN-8326-1) (Red Hat Advisory, OpenSUSE Security, SUSE Bugzilla).

Community reactions

The OpenSUSE security team published a detailed advisory on January 7, 2026, describing the Foomuuri D-Bus authorization and argument injection issues, which was subsequently discussed on the oss-sec mailing list. Security news outlet SecurityOnline.info covered the vulnerabilities under the headline "Wide Open Firewall: Critical Foomuuri Flaws Let Local Users Take Control." The vulnerability received coverage from Linux-focused security outlets including LinuxSecurity.com and Pro-Linux.de, and was noted in the openSUSE planet roundup. Community reaction was moderate, reflecting the niche but security-critical nature of firewall management software (OpenSUSE Security, oss-sec).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78683CRITICAL9.4
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78682HIGH8.7
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78681HIGH8.7
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78680HIGH8.5
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78679HIGH7.1
  • Linux Debian logoLinux Debian
  • python-git
NoNoAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management