A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is needed as it's required to place the malicious policy file properly.
{
"cwe_ids": [
"CWE-787"
],
"cna_assigner": "redhat",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7519.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7519.json"
[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"194843406561665307492518022948441502460",
"256368177087476590824027693163048704477",
"289543494710369596500892213933305008941"
]
},
"target": {
"file": "src/polkitbackend/polkitbackendactionpool.c"
},
"source": "https://github.com/polkit-org/polkit/commit/107d3801361b9f9084f78710178e683391f1d245",
"signature_version": "v1",
"id": "CVE-2025-7519-13428640",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"function_hash": "170222943027964640532293278136544979486",
"length": 3300.0
},
"target": {
"function": "_start",
"file": "src/polkitbackend/polkitbackendactionpool.c"
},
"source": "https://github.com/polkit-org/polkit/commit/107d3801361b9f9084f78710178e683391f1d245",
"signature_version": "v1",
"id": "CVE-2025-7519-65be4b0f",
"deprecated": false
}
]
"2026-08-24T03:59:10Z"