CVE-2025-6019
High · CVSS 7.0libblockdev — Local Privilege Escalation via SUID-root XFS image resize through udisks (CWE-250)
- CVSS
- 7.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-250
Description
A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. However, a local attacker can create a specially crafted XFS image containing a SUID-root shell, then trick udisks into resizing it. This mounts their malicious filesystem with root privileges, allowing them to execute their SUID-root shell and gain complete control of the system.
Search profile — drives PoC discovery
Ranked PoCs (34) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 6
- ★ 4
- ★ 3
- ★ 71guinea-offensive-security/CVE-2025-6019 needs reviewgh_search · Shell
- ★ 17MichaelVenturella/CVE-2025-6018-6019-PoC needs reviewgh_search · Shell
- ★ 12gh_search · Shell
- ★ 40rionCollector/Exploit-Chain-CVE-2025-6018-6019 needs reviewgh_search · Shell
- ★ 4DesertDemons/CVE-2025-6018-6019 needs reviewgh_search · Shell
- ★ 4Goultarde/CVE-2025-6018_CVE-2025-6019_autopwn needs reviewgh_search · Shell
- ★ 2gh_search · Python
- ★ 1gh_search
- ★ 1localh0ste/CVE-2025-6018-and-CVE-2025-6019 needs reviewgh_search
- ★ 1symphony2colour/CVE-2025-6019-udisks-lpe-no-image needs reviewgh_search · Shell
- ★ 00x5chltz/CVE-2025-6019 needs reviewgh_search · Shell
- ★ 0B1ack4sh/Blackash-CVE-2025-6018 needs reviewtrickest
- ★ 0JustThinkingHard/Annual-project needs reviewtrickest
- ★ 0JustThinkingHard/HID-Attack needs reviewtrickest
- ★ 0MaxKappa/opensuse-leap-privesc-exploit needs reviewgh_search · Shell
- ★ 0PuddinCat/GithubRepoSpider needs reviewtrickest
- ★ 0boboaung1337/CVE-2025-6019 needs reviewgh_search · Shell
- ★ 0gh_search
- ★ 0fkie-cad/nvd-json-data-feeds needs reviewtrickest
- ★ 0harshitvarma05/CVE-2025-6019 needs reviewgh_search · Shell
- ★ 0gh_search · Shell
- ★ 0matesz44/CVE-2025-6018-19 needs reviewgh_search · Shell
- ★ 0mistrust999/PAM-UDisks-PrivEsc-Metasploit needs reviewtrickest
- ★ 0mistrustt/PAM-UDisks-PrivEsc-Metasploit needs reviewtrickest
- ★ 0pawan-shivarkar/List-of-CVE-s- needs reviewtrickest
- ★ 0pawan-shivarkar/pawan-shivarkar needs reviewtrickest
- ★ 0phamdinhquy2512/CVE-2025-6019-Exploitation needs reviewgh_search · Shell
- ★ 0robbin0919/CVE-2025-6019 needs reviewgh_search · Dockerfile
- ★ 0sultanovich/sultanovich-scripts-collection needs reviewtrickest
- ★ 0tr3m0x/CVE-2025-6019 needs reviewgh_search · Shell
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://access.redhat.com/errata/RHSA-2025:10796
- https://access.redhat.com/errata/RHSA-2025:9320
- https://access.redhat.com/errata/RHSA-2025:9321
- https://access.redhat.com/errata/RHSA-2025:9322
- https://access.redhat.com/errata/RHSA-2025:9323
- https://access.redhat.com/errata/RHSA-2025:9324
- https://access.redhat.com/errata/RHSA-2025:9325
- https://access.redhat.com/errata/RHSA-2025:9326
- https://access.redhat.com/errata/RHSA-2025:9327
- https://access.redhat.com/errata/RHSA-2025:9328
- https://access.redhat.com/errata/RHSA-2025:9878
- https://access.redhat.com/security/cve/CVE-2025-6019
Status: enriched · ingested 2026-06-30T12:00:22.000Z · profiled 2026-06-30T18:30:14.000Z