CVE-2025-6019 Information

Description

A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally the llow_active\ setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon an llow_active\ user on a system may be able escalate to full root privileges on the target host. Normally udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. However a local attacker can create a specially crafted XFS image containing a SUID-root shell then trick udisks into resizing it. This mounts their malicious filesystem with root privileges allowing them to execute their SUID-root shell and gain complete control of the system.

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

http://www.openwall.com/lists/oss-security/2025/06/17/5 http://www.openwall.com/lists/oss-security/2025/06/17/6 http://www.openwall.com/lists/oss-security/2025/06/18/1 https://access.redhat.com/security/cve/CVE-2025-6019 https://bugzilla.redhat.com/show_bug.cgi?id=2370051 https://lists.debian.org/debian-lts-announce/2025/06/msg00018.html

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.0

CNNVD-202506-2580 (Published: 2025-06-19)

Share on: