Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) and logrotate configuration shipped with Icinga 2 read the PID of the main Icinga 2 process from a PID file writable by the daemon user, but send the signal as the root user. This can allow the Icinga user to send signals to processes it would otherwise not permitted to. A fix is included in the following Icinga 2 versions: 2.15.1, 2.14.7, and 2.13.13.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Icinga
Icinga icinga |
|
| Vendors & Products |
Icinga
Icinga icinga |
Thu, 16 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Oct 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) and logrotate configuration shipped with Icinga 2 read the PID of the main Icinga 2 process from a PID file writable by the daemon user, but send the signal as the root user. This can allow the Icinga user to send signals to processes it would otherwise not permitted to. A fix is included in the following Icinga 2 versions: 2.15.1, 2.14.7, and 2.13.13. | |
| Title | Icinga 2 signals sent as root to processes based on PID file written by the Icinga 2 daemon user | |
| Weaknesses | CWE-250 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-10-16T17:20:14.705Z
Updated: 2025-10-16T19:23:18.312Z
Reserved: 2025-10-03T22:21:59.614Z
Link: CVE-2025-61909
Updated: 2025-10-16T18:29:07.517Z
Status : Awaiting Analysis
Published: 2025-10-16T18:15:38.427
Modified: 2025-10-21T19:31:50.020
Link: CVE-2025-61909
No data.