CVE-2025-6019: Libblockdev: lpe from allow_active to root in libblockdev via udisks
A flaw was found in Libblockdev. Libblockdev is vulnerable to Local Privilege Escalation (LPE) via allowactive to root via udisk.
Other sources
A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allowactive" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allowactive" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. However, a local attacker can create a specially crafted XFS image containing a SUID-root shell, then trick udisks into resizing it. This mounts their malicious filesystem with root privileges, allowing them to execute their SUID-root shell and gain complete control of the system.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6019?
CVE-2025-6019 is classified as a Local Privilege Escalation (LPE) vulnerability, which allows an attacker to gain root privileges.
How do I fix CVE-2025-6019?
To fix CVE-2025-6019, update the libblockdev package to the latest version provided by your distribution.
Who is affected by CVE-2025-6019?
CVE-2025-6019 affects all versions of libblockdev that utilize the 'allow_active' setting in Polkit.
What type of vulnerability is CVE-2025-6019?
CVE-2025-6019 is a Local Privilege Escalation (LPE) vulnerability allowing unauthorized root access.
Can CVE-2025-6019 be exploited remotely?
CVE-2025-6019 requires local access to the system, thus it cannot be exploited remotely.