• News/
  • bleepingcomputer-20250618084536

New Linux udisks flaw lets attackers get root on major Linux distros

BleepingComputer
·
Published Jun 18, 2025
·
Updated

Attackers can exploit two newly discovered local privilege escalation (LPE) vulnerabilities to gain root privileges on systems running major Linux distributions. The first flaw (tracked as CVE-2025-6018) was found in the configuration of the Pluggable Authentication Modules (PAM) framework on openSUSE Leap 15 and SUSE Linux Enterprise 15, allowing local attackers to gain the privileges of the "allow_active" user. The other security bug (CVE-2025-6019) was discovered in libblockdev, and it enables an "allow_active" user to gain root permissions via the udisks daemon (a storage management service that runs by default on most Linux distributions). While successfully abusing the two flaws as part of a "local-to-root" chain exploit can let attackers quickly gain root and completely take over a SUSE system, the libblockdev/udisks flaw is also extremely dangerous on its own. "Although it nominally requires 'allow_active' privileges, udisks ships by default on almost all Linux distributions, so nearly any system is vulnerable," said Qualys TRU senior manager Saeed Abbasi. "Techniques to gain 'allow_active,' including the PAM issue disclosed here, further negate that barrier. An attacker can chain these vulnerabilities for immediate root compromise with minimal effort." The Qualys Threat Research Unit (TRU), which discovered and reported both flaws, has also developed proof-of-concept exploits and successfully targeted CVE-2025-6019 to get root privileges on Ubuntu, Debian, Fedora, a...

Read full article

Affected Software

4 affected components
openSUSE Leap=15
SUSE Linux Enterprise=15
Libblockdev libblockdev
udisks udisks daemon (udisks)
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses newly discovered local privilege escalation vulnerabilities in the udisks component of major Linux distributions.

2

What security implications are discussed?

The vulnerabilities allow attackers to gain root privileges on systems running affected Linux distributions.

3

What specific vulnerabilities are mentioned in the article?

The article highlights two vulnerabilities, including CVE-2025-6018 related to the Pluggable Authentication Modules configuration.

4

Which Linux distributions are affected by the udisks flaws?

The vulnerabilities impact major Linux distributions, specifically SUSE Opensuse Leap and SUSE Linux Enterprise.

5

What is the timeline for exploitation of these vulnerabilities?

The exploitation of these vulnerabilities is listed in the Known Exploited Vulnerabilities (KEV) database with an expected date of July 2, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203