CVE-2025-7519

Source
https://cve.org/CVERecord?id=CVE-2025-7519
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7519.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-7519
Downstream
Related
Published
2025-07-14T13:35:21.280Z
Modified
2026-08-24T03:59:10.074331Z
Severity
  • 6.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write
Details

A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is needed as it's required to place the malicious policy file properly.

Database specific
{
    "cwe_ids": [
        "CWE-787"
    ],
    "cna_assigner": "redhat",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7519.json"
}
References

Affected packages

Git / github.com/polkit-org/polkit

Affected ranges

Type
GIT
Repo
https://github.com/polkit-org/polkit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "126"
        }
    ]
}

Affected versions

0.*
0.100
0.101
0.102
0.103
0.104
0.105
0.106
0.107
0.108
0.109
0.110
0.111
0.112
0.113
0.114
0.115
0.116
0.117
0.118
0.119
0.120
0.91
0.92
0.93
0.94
0.95
0.96
0.97
0.98
0.99
Other
121
122
123
124
125
126
POLICY_KIT_0_3
POLICY_KIT_0_4
POLICY_KIT_0_5
POLICY_KIT_0_6
POLICY_KIT_0_7
POLICY_KIT_0_8
POLICY_KIT_0_9
start

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7519.json"
vanir_signatures
[
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "194843406561665307492518022948441502460",
                "256368177087476590824027693163048704477",
                "289543494710369596500892213933305008941"
            ]
        },
        "target": {
            "file": "src/polkitbackend/polkitbackendactionpool.c"
        },
        "source": "https://github.com/polkit-org/polkit/commit/107d3801361b9f9084f78710178e683391f1d245",
        "signature_version": "v1",
        "id": "CVE-2025-7519-13428640",
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "170222943027964640532293278136544979486",
            "length": 3300.0
        },
        "target": {
            "function": "_start",
            "file": "src/polkitbackend/polkitbackendactionpool.c"
        },
        "source": "https://github.com/polkit-org/polkit/commit/107d3801361b9f9084f78710178e683391f1d245",
        "signature_version": "v1",
        "id": "CVE-2025-7519-65be4b0f",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-08-24T03:59:10Z"