Linux Privilege Escalation Exploit Released – udisksd & libblockdev Vulnerability
ID: c1cdf809-8eb6-51ec-9a63-4e362f9c94b7
STIX ID: report--c1cdf809-8eb6-51ec-9a63-4e362f9c94b7
Feed Name: Cyber Press
In June 2025 researchers disclosed CVE-2025-6019: a critical local privilege escalation in udisksd/libblockdev that permits users in the 'allow_active' group to gain root via forged or misvalidated D-Bus disk operations; the report includes PoC code showing root-controlled mounts, analysis of the trust-boundary failure, and vendor patches enforcing UID-based checks and stricter Polkit rules—organizations should update udisks2/libblockdev and audit group/Polkit configurations immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
