PT-2025-25766 · Unknown+10 · Libblockdev+10

Jakub Wilk

·

Published

2025-05-14

·

Updated

2026-05-16

·

CVE-2025-6019

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libblockdev versions prior to 2.23-2ubuntu3+esm1 libblockdev versions prior to 3.1.1-2ubuntu0.1 libblockdev (affected versions not specified)
Description A Local Privilege Escalation (LPE) issue exists in libblockdev due to how it interacts with the udisks daemon. The "allow active" setting in Polkit allows physically present users to perform specific actions based on their session type. While udisks typically mounts user-provided filesystem images using security flags such as nosuid and nodev to prevent privilege escalation, a local attacker can bypass these protections. By creating a specially crafted XFS image containing a SUID-root shell and tricking udisks into resizing it, the malicious filesystem is mounted with root privileges. This allows the attacker to execute the SUID-root shell and gain complete control of the target host.
Recommendations Update to version 2.23-2ubuntu3+esm1. Update to version 3.1.1-2ubuntu0.1. Upgrade libblockdev packages to the latest available version.

Fix

LPE

Weakness Enumeration

Related Identifiers

ALSA-2025:9327
ALSA-2025:9328
ALSA-2025:9878
ALSA-2025:A004
ALSA-2025:A005
ALSA-2025:A006
ALT-PU-2025-8230
ALT-PU-2025-9056
ALT-PU-2025-9371
AZL-64187
AZL-64190
BDU:2025-07084
CESA-2025_9878
CVE-2025-6019
DLA-4221-1
DSA-5943-1
INFSA-2025_9327
INFSA-2025_9878
MGASA-2025-0188
OESA-2025-1677
OESA-2025-1688
OPENSUSE-SU-2025:15237-1
RHSA-2025:10796
RHSA-2025:9320
RHSA-2025:9321
RHSA-2025:9322
RHSA-2025:9323
RHSA-2025:9324
RHSA-2025:9325
RHSA-2025:9326
RHSA-2025:9327
RHSA-2025:9328
RHSA-2025:9878
RHSA-2025_9327
RHSA-2025_9878
SUSE-SU-2025:02043-1
SUSE-SU-2025:02044-1
SUSE-SU-2025:20426-1
SUSE-SU-2025:20440-1
SUSE-SU-2025_02043-1
SUSE-SU-2025_02044-1
USN-7577-1
USN-7577-2
USN-7578-1
USN-7578-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Libblockdev