Monday, 7 July, 2025
PoC Released for Critical Linux Privilege Escalation via udisksd & libblockdev

A Proof-of-Concept exploit for CVE-2025-6019 demonstrates how unprivileged users in the allow_active group can leverage a flaw in the udisksd daemon and its libblockdev library to gain root privileges via manipulated D-Bus calls. A simple udisksctl mount -b /dev/loop0 can execute mount operations with elevated permissions. Fedora and SUSE defaults are especially at risk—admins must update packages and tighten Polkit rules immediately.
Read full story at Cybersecurity News