CVE-2025-6019

EUVD-2025-18685
A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation.  However, a local attacker can create a specially crafted XFS image containing a SUID-root shell, then trick udisks into resizing it. This mounts their malicious filesystem with root privileges, allowing them to execute their SUID-root shell and gain complete control of the system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Debian logo
Debian Releases
Debian Product
Codename
libblockdev
bookworm
2.28-2+deb12u1
fixed
bookworm (security)
2.28-2+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
2.25-2+deb11u1
fixed
forky
3.5.0-1
fixed
sid
3.5.0-1
fixed
trixie
3.3.0-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libblockdev
bionic
Fixed 2.16-2ubuntu0.1~esm1
released
focal
Fixed 2.23-2ubuntu3+esm1
released
jammy
Fixed 2.26-1ubuntu0.1
released
noble
Fixed 3.1.1-1ubuntu0.1
released
oracular
Fixed 3.1.1-2ubuntu0.1
released
plucky
Fixed 3.3.0-2ubuntu0.1
released
questing
not-affected
udisks2
bionic
Fixed 2.7.6-3ubuntu0.2+esm1
released
focal
Fixed 2.8.4-1ubuntu2+esm1
released
jammy
Fixed 2.9.4-1ubuntu2.2
released
noble
Fixed 2.10.1-6ubuntu1.2
released
oracular
Fixed 2.10.1-9ubuntu3.2
released
plucky
Fixed 2.10.1-11ubuntu2.2
released
questing
Fixed 2.10.1-12.1ubuntu1
released
trusty
not-affected
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libbd_crypto2
suse enterprise desktop 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise desktop 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP2
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP3
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP7
2.26-150400.3.5.1
fixed
libbd_fs2
suse enterprise desktop 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise desktop 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP2
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP3
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP7
2.26-150400.3.5.1
fixed
libbd_loop2
suse enterprise desktop 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise desktop 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP2
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP3
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP7
2.26-150400.3.5.1
fixed
libbd_lvm2
suse enterprise desktop 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise desktop 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP7
2.26-150400.3.5.1
fixed
libbd_mdraid2
suse enterprise desktop 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise desktop 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP2
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP3
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP7
2.26-150400.3.5.1
fixed
libbd_part2
suse enterprise desktop 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise desktop 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP2
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP3
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP7
2.26-150400.3.5.1
fixed
libbd_swap2
suse enterprise desktop 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise desktop 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP2
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP3
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP7
2.26-150400.3.5.1
fixed
libbd_utils2
suse enterprise desktop 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise desktop 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP2
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP3
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP7
2.26-150400.3.5.1
fixed
libblockdev
suse enterprise desktop 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise desktop 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP2
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP3
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP7
2.26-150400.3.5.1
fixed
libblockdev2
suse enterprise desktop 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise desktop 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise sap 15 SP7
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP2
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP3
2.22-150200.3.3.1
fixed
suse enterprise server 15 SP4
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP6
2.26-150400.3.5.1
fixed
suse enterprise server 15 SP7
2.26-150400.3.5.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libblockdev
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-crypto
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-crypto-devel
RHEL 8
0:2.28-7.el8_10
fixed
libblockdev-devel
RHEL 8
0:2.28-7.el8_10
fixed
libblockdev-dm
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-fs
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-fs-devel
RHEL 8
0:2.28-7.el8_10
fixed
libblockdev-kbd
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-loop
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-loop-devel
RHEL 8
0:2.28-7.el8_10
fixed
libblockdev-lvm
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-lvm-dbus
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-lvm-devel
RHEL 8
0:2.28-7.el8_10
fixed
libblockdev-mdraid
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-mdraid-devel
RHEL 8
0:2.28-7.el8_10
fixed
libblockdev-mpath
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-nvdimm
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-nvme
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-part
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-part-devel
RHEL 8
0:2.28-7.el8_10
fixed
libblockdev-plugins-all
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-s390
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-swap
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-swap-devel
RHEL 8
0:2.28-7.el8_10
fixed
libblockdev-tools
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-utils
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed
libblockdev-utils-devel
RHEL 8
0:2.28-7.el8_10
fixed
libblockdev-vdo
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
libblockdev-vdo-devel
RHEL 8
0:2.28-7.el8_10
fixed
python3-blockdev
RHEL 8
0:2.28-7.el8_10
fixed
RHEL 8.2 AUS
0:2.19-13.el8_2
fixed
RHEL 8.4 AUS
0:2.24-6.el8_4
fixed
RHEL 8.6 AUS
0:2.24-9.el8_6
fixed
RHEL 8.6 E4S
0:2.24-9.el8_6
fixed
RHEL 8.6 TUS
0:2.24-9.el8_6
fixed
RHEL 8.8 E4S
0:2.28-3.el8_8
fixed
RHEL 9
0:2.28-14.el9_6
fixed