CVE-2025-6019

Source
https://cve.org/CVERecord?id=CVE-2025-6019
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6019.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-6019
Downstream
Related
Published
2025-06-19T11:55:57.380Z
Modified
2026-07-15T01:49:03.208975868Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Libblockdev: lpe from allow_active to root in libblockdev via udisks
Details

A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allowactive" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allowactive" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. However, a local attacker can create a specially crafted XFS image containing a SUID-root shell, then trick udisks into resizing it. This mounts their malicious filesystem with root privileges, allowing them to execute their SUID-root shell and gain complete control of the system.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6019.json",
    "cwe_ids": [
        "CWE-250"
    ],
    "cna_assigner": "redhat"
}
References

Affected packages

Git / github.com/storaged-project/libblockdev

Affected ranges

Type
GIT
Repo
https://github.com/storaged-project/libblockdev
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.3.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.1-1
0.10-1
0.11-1
0.13-1
0.2-1
0.3-1
0.4-1
0.5-1
0.6-1
0.7-1
0.8-1
1.*
1.0-1
1.1-1
1.2-1
1.3-1
1.4-1
1.5-1
2.*
2.0-1
2.1-1
2.10-1
2.11-1
2.12-1
2.13-1
2.14-1
2.15-1
2.16-1
2.17-1
2.18-1
2.19-1
2.2-1
2.20-1
2.21-1
2.22-1
2.23-1
2.3-1
2.4-1
2.5-1
2.6-1
2.7-1
2.8-1
2.9-1
3.*
3.0-1
3.0.1-1
3.0.2-1
3.0.3-1
3.0.4-1
3.1.0-1
3.2.0
3.3.0
libblockdev-0.*
libblockdev-0.1-1
libblockdev-0.10-1
libblockdev-0.11-1
libblockdev-0.13-1
libblockdev-0.2-1
libblockdev-0.3-1
libblockdev-0.4-1
libblockdev-0.5-1
libblockdev-0.6-1
libblockdev-0.7-1
libblockdev-0.8-1
libblockdev-1.*
libblockdev-1.0-1
libblockdev-1.1-1
libblockdev-1.2-1
libblockdev-1.3-1
libblockdev-1.4-1
libblockdev-1.5-1
libblockdev-2.*
libblockdev-2.0-1
libblockdev-2.1-1
libblockdev-2.10-1
libblockdev-2.11-1
libblockdev-2.12-1
libblockdev-2.2-1
libblockdev-2.3-1
libblockdev-2.4-1
libblockdev-2.5-1
libblockdev-2.6-1
libblockdev-2.7-1
libblockdev-2.8-1
libblockdev-2.9-1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6019.json"