CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-6019

High · CVSS 7.0

libblockdev — Local Privilege Escalation via SUID-root XFS image resize through udisks (CWE-250)

CVSS
7.0
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-250

Description

A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. However, a local attacker can create a specially crafted XFS image containing a SUID-root shell, then trick udisks into resizing it. This mounts their malicious filesystem with root privileges, allowing them to execute their SUID-root shell and gain complete control of the system.

Search profile — drives PoC discovery

Symbols allow_activenosuidnodevudisksxfs_growfsbd_fs_resizeudisks2PolkitSUID-root shellXFS imagelibblockdev-fs
Keywords CVE-2025-6019libblockdevudiskslocal privilege escalationXFS SUIDPolkit allow_activefilesystem resize LPEnosuid bypassudisks mount suidlibblockdev LPEXFS crafted image root
Versions: All versions prior to patched builds referenced in RHSA-2025:9320 / RHSA-2025:10796

Ranked PoCs (34) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-30T12:00:22.000Z · profiled 2026-06-30T18:30:14.000Z