CVE-2025-7519
EUVD-2025-2135014.07.2025, 14:15
A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is needed as it's required to place the malicious policy file properly.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | openshift_container_platform | 4.0 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libpolkit-agent-1-0-121 |
| ||||||||||||||
| libpolkit-gobject-1-0-121 |
| ||||||||||||||
| libpolkit0 |
| ||||||||||||||
| pkexec-121 |
| ||||||||||||||
| polkit |
| ||||||||||||||
| polkit-121 |
| ||||||||||||||
| polkit-devel |
| ||||||||||||||
| polkit-devel-121 |
| ||||||||||||||
| typelib-1_0-Polkit-1_0 |
| ||||||||||||||
| typelib-1_0-Polkit-1_0-121 |
|
Common Weakness Enumeration