天下漏洞,尽知其名
HIGH

CVE-2026-53605 Reachy Mini ISO 本地提权漏洞

影响本地攻击者可提升至 root 权限,完全控制设备

AI 研判

Reachy Mini ISO for Wireless 是用于构建 Reachy Mini Wireless 机器人 Raspberry Pi OS 镜像的组件。在 0.2.4 版本之前,其 sudoers 配置为 pollen 守护进程用户(uid 1000)授予了对 /usr/bin/systemctl 的无密码 sudo 权限,且未限制子命令或参数。这构成一个本地权限提升漏洞,任何以 pollen 身份运行的进程都能在无需额外漏洞和用户交互的情况下获取 root 权限。

影响范围

Reachy Mini ISO

Reachy Mini ISO for Wireless 0.2.4 之前的版本。

漏洞详情

漏洞类型为本地权限提升(LPE),成因是 sudoers 条目过于宽泛:pollen 用户可无密码执行 /usr/bin/systemctl,且未限制子命令或参数。攻击者可利用 systemctl 的功能(如启动恶意服务或执行任意命令)在三条命令内获得 uid 0 的 root 权限。该利用无需额外漏洞,也无需用户交互。

利用条件与风险

利用前提是攻击者已能以 pollen 用户身份在设备上执行进程,属于本地攻击。一旦满足,可完全控制设备,风险较高。

修复建议

官方已在 0.2.4 版本中修复,建议升级至 0.2.4 或更高版本。临时缓解措施为收紧 sudoers 配置,移除 pollen 用户对 systemctl 的无限制无密码 sudo 权限。

原始情报

Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.