CVE-2025-6018
High · CVSS 7.8pam-config / Linux PAM (Pluggable Authentication Modules) — Local Privilege Escalation (LPE) via incorrect Polkit allow_active authorization (CWE-863 Incorrect Authorization)
- CVSS
- 7.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-863
Description
A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via SSH) to obtain the elevated privileges normally reserved for a physically present, "allow_active" user. The highest risk is that the attacker can then perform all allow_active yes Polkit actions, which are typically restricted to console users, potentially gaining unauthorized control over system configurations, services, or other sensitive operations.
Search profile — drives PoC discovery
Ranked PoCs (25) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 11
- ★ 23m4sh-wacker/CVE-2025-60188-Atarim-Plugin-Exploit needs reviewgh_search · Python
- ★ 17MichaelVenturella/CVE-2025-6018-6019-PoC needs reviewgh_search · Shell
- ★ 12gh_search · Shell
- ★ 6dreysanox/CVE-2025-6018_Poc needs reviewgh_search · Python
- ★ 40rionCollector/Exploit-Chain-CVE-2025-6018-6019 needs reviewgh_search · Shell
- ★ 4DesertDemons/CVE-2025-6018-6019 needs reviewgh_search · Shell
- ★ 4Goultarde/CVE-2025-6018_CVE-2025-6019_autopwn needs reviewgh_search · Shell
- ★ 1gh_search
- ★ 1iamgithubber/CVE-2025-6018-19-exploit needs reviewgh_search · Shell
- ★ 1localh0ste/CVE-2025-6018-and-CVE-2025-6019 needs reviewgh_search
- ★ 0B1ack4sh/Blackash-CVE-2025-6018 needs reviewtrickest
- ★ 0MaxKappa/opensuse-leap-privesc-exploit needs reviewgh_search · Shell
- ★ 0PuddinCat/GithubRepoSpider needs reviewtrickest
- ★ 0e1arth/CVE-2025-6018 needs reviewgh_search · Shell
- ★ 0gh_search
- ★ 0fkie-cad/nvd-json-data-feeds needs reviewtrickest
- ★ 0gh_search · Shell
- ★ 0matesz44/CVE-2025-6018-19 needs reviewgh_search · Shell
- ★ 0mistrust999/PAM-UDisks-PrivEsc-Metasploit needs reviewtrickest
- ★ 0mistrustt/PAM-UDisks-PrivEsc-Metasploit needs reviewtrickest
- ★ 0pawan-shivarkar/List-of-CVE-s- needs reviewtrickest
- ★ 0pawan-shivarkar/pawan-shivarkar needs reviewtrickest
- ★ 0sultanovich/sultanovich-scripts-collection needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://access.redhat.com/security/cve/CVE-2025-6018
- https://bugzilla.redhat.com/show_bug.cgi?id=2372693
- https://bugzilla.suse.com/show_bug.cgi?id=1243226
- https://cdn2.qualys.com/2025/06/17/suse15-pam-udisks-lpe.txt
- http://www.openwall.com/lists/oss-security/2025/08/28/4
- https://cdn2.qualys.com/2025/06/17/suse15-pam-udisks-lpe.txt
Status: enriched · ingested 2026-06-30T12:00:22.000Z · profiled 2026-06-30T18:30:14.000Z