{"id":4714,"date":"2025-06-18T10:03:34","date_gmt":"2025-06-18T10:03:34","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/18\/critical-linux-privilege-escalation-vulnerabilities-let-attackers-gain-full-root-access\/"},"modified":"2025-06-18T10:03:34","modified_gmt":"2025-06-18T10:03:34","slug":"critical-linux-privilege-escalation-vulnerabilities-let-attackers-gain-full-root-access","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/18\/critical-linux-privilege-escalation-vulnerabilities-let-attackers-gain-full-root-access\/","title":{"rendered":"Critical Linux Privilege Escalation Vulnerabilities Let Attackers Gain Full Root Access"},"content":{"rendered":"<p>    Critical Linux Privilege Escalation Vulnerabilities Let Attackers Gain Full Root Access<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Two critical, interconnected flaws, CVE-2025-6018 and CVE-2025-6019, enable unprivileged attackers to achieve root access on major Linux distributions.<\/p>\n<p>Affecting millions worldwide, these vulnerabilities pose a severe security emergency that demands immediate patching.<\/p>\n<p>The first vulnerability exploits PAM configuration weaknesses in SUSE systems, while the second leverages the ubiquitous udisks daemon to escalate privileges to root level, creating a perfect storm for system compromise.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Linux Privilege Escalation Vulnerability Chain<\/strong><\/h2>\n<p>The vulnerability chain uncovered by Qualys Threat Research Unit begins with CVE-2025-6018, a local privilege escalation flaw residing in the Pluggable Authentication Modules (PAM) configuration of openSUSE Leap 15 and SUSE Linux Enterprise 15.\u00a0<\/p>\n<p>This misconfiguration allows unprivileged attackers connecting via SSH to elevate their status to \u201callow_active\u201d users, a designation typically reserved for physically present users at the console.\u00a0<\/p>\n<p>This initial foothold becomes the launching point for the more devastating second attack.<\/p>\n<p>CVE-2025-6019 targets libblockdev, a critical library accessible through the udisks daemon that ships by default on virtually all <a href=\"https:\/\/cybersecuritynews.com\/linux-kernels-nftables-vulnerability-poc\/\" target=\"_blank\" rel=\"noreferrer noopener\">Linux distributions<\/a>.\u00a0<\/p>\n<p>Once an attacker achieves \u201callow_active\u201d status, this vulnerability provides a direct pathway to full root privileges.\u00a0<\/p>\n<p>The combination is particularly dangerous because udisks is pre-installed on mainstream distributions including Ubuntu, Debian, Fedora, and openSUSE, making the attack surface nearly universal.\u00a0<\/p>\n<p>Qualys researchers have successfully demonstrated proof-of-concept exploits across these platforms, confirming the widespread nature of the threat.<\/p>\n<p>The attack leverages fundamental Linux system components that handle authentication and device management.\u00a0<\/p>\n<p>The PAM framework controls user authentication and session establishment, determining which users qualify as \u201cactive\u201d for privileged operations.<\/p>\n<p>In affected SUSE systems, the PAM stack incorrectly treats remote SSH sessions as equivalent to local console access, granting polkit permissions that should remain restricted to physically present users.<\/p>\n<p>The second stage exploits the udisks2 service, which provides a D-Bus interface for storage management operations including mounting, querying, and formatting block devices, reads the <a href=\"https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2025\/06\/17\/qualys-tru-uncovers-chained-lpe-suse-15-pam-to-full-root-via-libblockdev-udisks\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">report<\/a>.<\/p>\n<p>The service communicates with libblockdev to perform low-level device operations. The vulnerability specifically targets the \u201corg.freedesktop.udisks2.modify-device\u201d polkit action, which by default allows any active user to modify devices.\u00a0<\/p>\n<p>An attacker with \u201callow_active\u201d status can manipulate this interface to execute arbitrary code with root privileges, completing the privilege escalation chain.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>CVEs<\/strong><\/td>\n<td><strong>Affected Products<\/strong><\/td>\n<td><strong>Impact<\/strong><\/td>\n<td>\n<strong>Exploit Prerequisites<\/strong><strong><\/strong>\n<\/td>\n<td><strong>CVSS 3.1 Score<\/strong><\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-6018<\/td>\n<td>openSUSE Leap 15SUSE Linux Enterprise 15<\/td>\n<td>Elevation to \u201callow_active\u201d user<\/td>\n<td>Local access (e.g., SSH) to vulnerable PAM configuration<\/td>\n<td>8.8 (High)\n<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-6019<\/td>\n<td>libblockdev packageudisks daemon (Ubuntu, Debian, Fedora, openSUSE Leap 15+)<\/td>\n<td>Full root privileges<\/td>\n<td>\u201callow_active\u201d context (e.g., via CVE-2025-6018 or physical console access)<\/td>\n<td>7.8 (High)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\"><strong>Urgent Mitigation Required\u00a0<\/strong><\/h2>\n<p>Organizations must implement immediate countermeasures to prevent exploitation of these vulnerabilities.\u00a0<\/p>\n<p>The primary mitigation involves modifying polkit rules for the \u201corg.freedesktop.udisks2.modify-device\u201d action, changing the allow_active setting from \u201cyes\u201d to \u201cauth_admin\u201d to require administrator authentication.\u00a0<\/p>\n<p>This configuration change can be implemented by creating or modifying polkit rule files in \/etc\/polkit-1\/rules.d\/.<\/p>\n<p>Security teams should prioritize patching both <a href=\"https:\/\/cybersecuritynews.com\/yubico-pam-module-vulnerability-let-attackers-bypass-authentications\/\" target=\"_blank\" rel=\"noreferrer noopener\">PAM configurations<\/a> and libblockdev\/udisks components across their entire Linux infrastructure.\u00a0<\/p>\n<p>The vulnerability chain\u2019s reliance on default system packages means that virtually any Linux server or workstation could be vulnerable.\u00a0<\/p>\n<p>Given that root access enables attackers to disable security agents, install persistent backdoors, and move laterally through networks, a single compromised system can jeopardize the entire organizational infrastructure.\u00a0<\/p>\n<p>Patches should be deployed without delay, as the simplicity of exploitation makes these vulnerabilities an immediate and universal risk to Linux environments worldwide.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong><strong>Power up early threat detection, escalation, and mitigation with ANY.RUN\u2019s Threat Intelligence Lookup. <\/strong><a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn_jun&amp;utm_medium=article&amp;utm_campaign=how-to-detect-threats-early-for-fast-incident-response&amp;utm_content=plans&amp;utm_term=170625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Get 50 trial searches<\/strong><\/a><strong>.<\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/linux-privilege-escalation-vulnerabilities\/\">Critical Linux Privilege Escalation Vulnerabilities Let Attackers Gain Full Root Access<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/linux-privilege-escalation-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Linux Privilege Escalation Vulnerabilities Let Attackers Gain Full Root Access Two critical, interconnected flaws, CVE-2025-6018 and CVE-2025-6019, enable unprivileged attackers to achieve root access on major Linux distributions. Affecting millions worldwide, these vulnerabilities pose a severe security emergency that demands immediate patching. The first vulnerability exploits PAM configuration weaknesses in SUSE systems, while the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-4714","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4714"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4714"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4714\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}