CVE-2025-6019
A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. However, a local attacker can create a specially crafted XFS image containing a SUID-root shell, then trick udisks into resizing it. This mounts their malicious filesystem with root privileges, allowing them to execute their SUID-root shell and gain complete control of the system.
- CVSS v3.1
- 7.0 HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.46% chance of exploitation in the next 30 days, 38th percentile
- Published
- 2025-06-19
- Updated
- 2026-06-30
Proof-of-concept exploits (25)
- And-oss/CVE-2025-6019-exploit4★ · 2025-06-23
- JustThinkingHard/Annual-project0★ · 2025-07-08
- JustThinkingHard/HID-Attack0★ · 2025-07-08
- dreysanox/CVE-2025-6018_Poc6★ · 2025-07-21
- guinea-offensive-security/CVE-2025-601971★ · 2025-06-19
- harshitvarma05/CVE-2025-60190★ · 2025-09-23
- mistrust999/PAM-UDisks-PrivEsc-Metasploit3★ · 2025-06-27
- mistrustt/PAM-UDisks-PrivEsc-Metasploit3★ · 2025-06-27
- neko205-mx/CVE-2025-6019_Exploit3★ · 2025-06-29
- 0x5chltz/CVE-2025-6019
- JM00NJ/CVE-2025-6019-udisks2-XFS-Resize-TOCTOU-Privilege-Escalation
- boboaung1337/CVE-2025-6019
- phamdinhquy2512/CVE-2025-6019-Exploitation
- robbin0919/CVE-2025-6019
- symphony2colour/CVE-2025-6019-udisks-lpe-no-image
- tr3m0x/CVE-2025-6019
- 0rionCollector/Exploit-Chain-CVE-2025-6018-6019
- DesertDemons/CVE-2025-6018-6019
- Goultarde/CVE-2025-6018_CVE-2025-6019_autopwn
- MaxKappa/opensuse-leap-privesc-exploit
- MichaelVenturella/CVE-2025-6018-6019-PoC
- euxem/Analyse-faille-de-s-curit-CVE-2025-6018-CVE-2025-6019
- iOxsec/CVE-2025-6018-CVE-2025-6019-Privilege-Escalation-Exploit
- m0r4a/CVE-2026-6018-9-Local-Privilege-Escalation-Chain
- muyuanlove/CVE-2025-6018-CVE-2025-6019-Privilege-Escalation-Exploit