Qualys disclosed two local privilege escalation vulnerabilities that can be chained to obtain root on affected Linux systems: CVE-2025-6018 in the PAM configuration of openSUSE Leap 15 and SUSE Linux Enterprise 15, and CVE-2025-6019 in libblockdev reachable through udisks. The first flaw lets an unprivileged user logging in via sshd manipulate PAM environment variables through ~/.pam_environment, allowing the session to be treated by polkit as a physical allow_active user. The second flaw lets an allow_active user escalate to root by abusing udisks filesystem-resize operations, which cause libblockdev to temporarily mount an attacker-controlled XFS filesystem in /tmp without nosuid and nodev protections.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
A technical blog post published on Ubuntu 24.04 explained D-Bus and Polkit internals and discussed security case studies including CVE-2025-23222 in dde-api-proxy and CVE-2021-3560 in Polkit. It also demonstrated practical abuse paths involving bus-name ownership and session context.
Qualys published an advisory describing CVE-2025-6018, a PAM/polkit local privilege escalation affecting openSUSE Leap 15 and SUSE Linux Enterprise 15, and CVE-2025-6019, a libblockdev issue exploitable via udisks. The advisory showed that chaining the two flaws can let an unprivileged local attacker gain root.
Qualys said it sent the advisory draft along with SUSE and Red Hat patches to the linux-distros list as part of coordinated disclosure. This expanded pre-release notification beyond the initial vendor contacts.
Qualys said it reported a draft advisory covering CVE-2025-6018 and CVE-2025-6019 to SUSE and Red Hat. This marked the start of coordinated disclosure with the affected vendors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.