CVE-2025-27234

NameCVE-2025-27234
DescriptionZabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
zabbix (PTS)bullseye1:5.0.8+dfsg-1vulnerable
bullseye (security)1:5.0.46+dfsg-1+deb11u1vulnerable
bookworm1:6.0.14+dfsg-1fixed
forky, sid, trixie1:7.0.10+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zabbixsource(unstable)1:6.0.7+dfsg-2

Notes

https://support.zabbix.com/browse/ZBX-26985
5.0.0-5.0.46 specific issue, thus mark the first version in unstable from the
6.0.0 series onwards as the fixed version as workaround.
Fixed in 5.0.47

Search for package or bug name: Reporting problems