CVE-2025-6019 is a local privilege-escalation vulnerability in libblockdev reachable through the UDisks daemon. When UDisks resizes an XFS filesystem, libblockdev can temporarily mount an attacker-controlled filesystem without the nosuid and nodev protections normally applied to user-provided images. An attacker with a Polkit allow_active context can attach a crafted XFS image containing a set-user-ID root shell, request a resize operation, and retain the temporary mount long enough to execute the shell with root privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
23 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (7 hidden).
This repository is a small, two-stage local privilege-escalation PoC for CVE-2025-6019 targeting UDisks2’s XFS resize handling on Linux. It contains three files: a README, create_payload.sh, and exploit.sh. The first script prepares a malicious XFS image named payload.img using legacy XFS v4 formatting with intentional slack space, mounts it locally with sudo, and implants a target-compatible bash binary as rootbash with root ownership and mode 4755, effectively weaponizing the image with a SUID-root shell payload. The second script performs the exploitation flow on the target: it validates that the current user has an active login session via loginctl, kills gvfs-udisks2-volume-monitor, creates a loop device from the supplied image using udisksctl, starts a background watcher that probes for /tmp/blockdev*/rootbash, and then calls the UDisks2 system D-Bus method org.freedesktop.UDisks2.Filesystem.Resize on the loop device object path /org/freedesktop/UDisks2/block_devices/<loopdev>. After a short delay, it checks for the exposed SUID payload under /tmp/blockdev* and executes rootbash -p to obtain a root shell. The exploit is operational rather than a mere detector: it includes a concrete payload and exploitation logic, but payload customization is basic and manual. No external network C2 or remote endpoints are present; the attack surface is local file/device handling and system D-Bus interaction.
This repository is a small local privilege escalation exploit chain for SUSE/openSUSE systems, consisting of a detailed README and a single C payload. The README documents a two-stage attack: CVE-2025-6018 abuses PAM environment injection via ~/.pam_environment during SSH login to make a remote session appear physically active to polkit/systemd-logind, and CVE-2025-6019 abuses a libblockdev/udisks2 Filesystem.Resize race where an attacker-controlled XFS image is temporarily mounted without nosuid. The repository structure is minimal: README.md provides the full manual exploitation workflow, prerequisites, target validation, image preparation, transfer steps, D-Bus invocation, and remediation guidance; payload.c implements the race catcher used in the second stage. The exploit’s main capability is privilege escalation from an unprivileged local SSH user to root. The C program loops indefinitely over /proc/mounts, looking specifically for a mount entry containing both "loop1" and "xfs". When found, it extracts the mountpoint, executes the mounted bash binary with -p, copies /bin/bash to /tmp/rootbash, sets mode 4755, and then attempts to execute /tmp/rootbash -p to yield a root shell. This is operational exploit code rather than a detector: it contains a concrete payload and performs the final privilege-escalation step automatically. Notable fingerprintable artifacts include PAM and policy file paths (~/.pam_environment, /etc/pam.d/common-auth, /usr/share/polkit-1/actions/org.freedesktop.UDisks2.policy), D-Bus identifiers (org.freedesktop.UDisks2 and /org/freedesktop/UDisks2/block_devices/loop1), temporary and dropped files (/tmp/xfs.image, /tmp/payload, /tmp/rootbash, /tmp/blockdev.XXXXXX/), and the attacker-hosted HTTP transfer endpoints on port 8888. The payload is somewhat brittle because it hardcodes loop1 and assumes the temporary mount can be caught by polling /proc/mounts, but it is sufficient as an operational proof-of-concept for the documented exploit chain.
Repository purpose: a local privilege escalation exploit guide and Bash script chaining CVE-2025-6018 and CVE-2025-6019. The repo contains one main exploit script (exp.sh) plus English/Chinese walkthroughs (README.md, readme_zh-cn.md). Core exploit flow (exp.sh): 1) Environment validation: requires ~/.pam_environment to contain XDG_SEAT OVERRIDE=seat0 and XDG_VTNR OVERRIDE=1, and requires a fresh login so PAM env is active. It verifies authorization by calling system D-Bus org.freedesktop.login1.Manager.CanReboot and expects ('yes',). 2) Stability step: kills gvfs-udisks2-volume-monitor to avoid desktop automount/monitor interference. 3) Loop device creation: uses udisksctl loop-setup --file ~/xfs.image to create /dev/loopN. 4) Trigger vulnerable behavior/race: starts a background loop attempting to execute /tmp/blockdev*/bash, then calls org.freedesktop.UDisks2.Filesystem.Resize on the loop device object path. It tolerates/expects a 'target is busy' error and then searches /tmp for a SUID bash (find /tmp -maxdepth 2 -name bash -perm -4000). 5) Privilege escalation: executes the discovered SUID bash with -p to preserve privileges, verifies euid=0 via id, attempts to read /root/root.txt, and finally launches an interactive root shell. Operator-prepared payload: the documentation instructs creating an XFS image on a separate machine, copying /bin/bash into it, and setting mode 4755 (SUID). That image is then uploaded to the target as ~/xfs.image and used by the exploit to obtain root. Notable observables: D-Bus calls to org.freedesktop.login1 and org.freedesktop.UDisks2, creation of /dev/loop* devices, transient /tmp/blockdev_* paths, and execution of a SUID bash from /tmp. The README includes an example target IP (10.129.252.9) for SSH/SCP but the exploit itself is purely local and does not perform network scanning or callbacks.
Repository contains a single Bash local privilege-escalation exploit script (exp.sh) plus a README guide and MIT license. The README describes a two-CVE chain (CVE-2025-6018 + CVE-2025-6019) requiring: (1) creating an XFS image locally, mounting it, copying /bin/bash into it, and setting the SUID bit; (2) uploading exp.sh and xfs.image to the target; (3) setting PAM environment overrides in ~/.pam_environment (XDG_SEAT and XDG_VTNR) and logging out/in; (4) verifying session authorization via a system D-Bus call to org.freedesktop.login1.Manager.CanReboot returning ('yes',); then running exp.sh. exp.sh automates exploitation in five stages: environment validation (checks ~/.pam_environment, presence of ~/xfs.image, and CanReboot via gdbus), killing gvfs-udisks2-volume-monitor, creating a loop device from the XFS image using udisksctl loop-setup, triggering a UDisks2 Filesystem.Resize call on the loop device while a background loop probes /tmp/blockdev*/bash (aiming to hit a race/busy condition and expose the SUID bash under /tmp), and finally executing the discovered SUID bash with -p to confirm euid=0, optionally reading /root/root.txt, and spawning an interactive root shell. No external C2 infrastructure is present; all interactions are local to the target via system D-Bus, loop devices, and filesystem paths. The only network observables are example SSH/SCP commands in the README referencing 10.129.252.9.
Repository purpose: an automated exploit chain (“auto-pwn”) combining CVE-2025-6018 (PAM environment injection via ~/.pam_environment) and CVE-2025-6019 (UDisks2 privilege escalation via filesystem resize/mount behavior) to obtain root on SUSE/openSUSE Leap 15.x-like targets. Structure (5 files): - CVE-2025-6018_CVE-2025-6019_autopwn.py (Python): main automation tool. Uses Paramiko to SSH to a target with provided credentials, SFTP-downloads /bin/bash from the target, locally builds a crafted XFS image (xfs.image) containing a SUID-root bash, uploads xfs.image and exploit.sh to /tmp on the target, writes ~/.pam_environment with XDG_SEAT and XDG_VTNR overrides, reconnects to ensure PAM env is loaded, then runs “/tmp/exploit.sh stage3 /tmp/xfs.image” and waits for a root prompt. Provides an interactive shell over the SSH channel and performs cleanup (removes /tmp/xfs.image, /tmp/exploit.sh, ~/.pam_environment). - exploit.sh (Bash): multi-stage helper implementing the chain. Stage1 creates and formats an XFS image and places a SUID-root bash inside; Stage2 sets up PAM environment injection; Stage3 performs the UDisks2 exploitation path to make the SUID bash usable and pop a root shell (full stage3 logic is truncated in provided content, but usage text and Python driver indicate it is invoked as stage3 with the image path). - README.md: explains the chained attack, prerequisites, and usage. - requirements.txt: paramiko dependency. - .gitignore: ignores xfs.image and target_bash artifacts. Exploit capabilities: - Remote orchestration over SSH (credentialed access required). - Local preparation of a malicious filesystem image (XFS) embedding a SUID-root shell. - Target-side PAM environment poisoning by writing ~/.pam_environment to influence session/authorization (XDG_SEAT/XDG_VTNR). - Triggering target-side UDisks2 action (stage3) to achieve local privilege escalation to root. - Interactive root shell handling and post-exploit cleanup. Notable observables/fingerprintable artifacts: - Remote files: /tmp/xfs.image, /tmp/exploit.sh, ~/.pam_environment. - Local artifacts: xfs.image, ./target_bash, temporary mount directory (./mnt_ptr in Python; mktemp dir in bash stage1). - Network: SSH connections to the provided target IP (default TCP/22).
Repository provides a local privilege escalation exploit chain for CVE-2025-6019 (udisks2 XFS resize TOCTOU/race). It is not a framework module; it is a small multi-script PoC/operational exploit. Structure and purpose: - bypass.py: Writes to ~/.pam_environment to spoof a local graphical/seat session (XDG_SEAT=seat0, XDG_VTNR=1). This is intended to bypass Polkit restrictions that commonly block udisks2 operations from remote sessions (e.g., SSH/containers). Requires user logout/login to take effect. - weapon.py: Creates a weaponized XFS filesystem image at /dev/shm/xfs_ram.img. It generates a mkfs.xfs protofile (/dev/shm/proto.txt) that instructs mkfs.xfs to create a file named 'pwnbash' inside the filesystem with SUID permissions (mode -u-755) and owned by root (0:0), using the system bash binary as the file contents. It adjusts PATH to find mkfs.xfs in sbin locations. - trigger.sh: Implements the race trigger. In a loop (multi-threaded via background jobs), it uses udisksctl loop-setup on the weaponized image to create /dev/loopN, repeatedly truncates the backing image to change its size, and calls the system D-Bus method org.freedesktop.UDisks2.Filesystem.Resize on the corresponding /org/freedesktop/UDisks2/block_devices/loopN object. It sleeps briefly (0.1s) to target the window where udisks2 creates a temporary mount directory under /tmp (documented as /tmp/blockdev.XXXXXX) before restrictive permissions and/or nosuid are applied, then deletes the loop device to keep state unstable. Exploit capabilities: - Local LPE to root by achieving execution of an embedded SUID-root bash (pwnbash) from the temporary mountpoint during the race window (README suggests running './pwnbash -p'). - Includes a Polkit/session-context bypass helper (PAM environment injection) to make udisks2 operations available to non-local sessions. Notable observables/fingerprintable targets: - Files modified/created: ~/.pam_environment, /dev/shm/xfs_ram.img, /dev/shm/proto.txt, and temporary udisks2 mountpoints under /tmp/blockdev.*. - D-Bus target: org.freedesktop.UDisks2 on the system bus; method org.freedesktop.UDisks2.Filesystem.Resize; object paths /org/freedesktop/UDisks2/block_devices/loopN. Overall, the repo is an operational exploit chain (not just detection) that weaponizes an XFS image with a SUID payload and then triggers a udisks2 resize race via D-Bus to obtain a root shell.
Repository contains a single Bash exploit script (exploit.sh) plus README and LICENSE. The README documents a local privilege escalation chain for openSUSE Leap 15.6 combining CVE-2025-6018 (PAM/pam_systemd environment manipulation to obtain polkit 'allow_active') and CVE-2025-6019 (UDisks2/libblockdev behavior allowing an attacker-controlled filesystem to be mounted under /tmp without nosuid, enabling SUID execution). Exploit flow in exploit.sh: 1) Validates presence of an attacker-supplied XFS image (default: xfs.image) that must contain a SUID-root /bash. 2) Checks current polkit/console-like privilege by calling system D-Bus login1 Manager.CanReboot; if not 'yes', it writes ~/.pam_environment with XDG_SEAT=seat0 and XDG_VTNR=1 overrides and instructs the user to log out and back in so PAM applies the environment (CVE-2025-6018 step). 3) Once privileges are present, it sets up a loop device from the XFS image via udisksctl, then triggers org.freedesktop.UDisks2.Filesystem.Resize on that loop block device over system D-Bus (CVE-2025-6019 step). It races/loops looking for /tmp/blockdev*/bash and executes it with bash -p, verifying euid=0, then execs an interactive root shell. No network scanning or remote exploitation is present; the attack is purely local and depends on system services (login1, udisks2) reachable over the system D-Bus and on a prepared filesystem image payload.
Repository contains a PoC/operational local privilege escalation exploit for CVE-2025-6019 described as a UDisks2 XFS resize privesc. Structure: - Readme.md: Describes the PoC, requirements (mkfs.xfs, udisksctl, gdbus, loginctl, sudo on build host), and usage flow. - create_payload.sh: Builds a crafted XFS image (payload.img) with legacy XFS settings (mkfs.xfs -m crc=0) and intentional slack space (image size 500MB, formatted size 350MB). It mounts the image with sudo, copies in a target-compatible bash binary as rootbash, and sets it to SUID root (chown root:root; chmod 4755). This produces the payload artifact to transfer to the target. - exploit.sh: Runs on the target. It validates an active systemd-logind session for the current user (loginctl list-sessions/show-session). It kills gvfs-udisks2-volume-monitor (likely to reduce interference), sets up a loop device from the provided image via udisksctl loop-setup, then triggers the vulnerable path by calling the UDisks2 D-Bus method org.freedesktop.UDisks2.Filesystem.Resize on the loop device’s object path. After a short wait, it searches for /tmp/blockdev* and attempts to execute /tmp/blockdev*/rootbash with -p to obtain a root shell. A background loop (“busy-keeper”) repeatedly tries to run /tmp/blockdev*/rootbash -c 'sleep 10; ...' to keep the filesystem busy/accessible during the race/resize behavior. Capabilities: - Creates a weaponized filesystem image containing a SUID-root shell payload. - Interacts with UDisks2 over the system D-Bus to invoke Filesystem.Resize on a loop-mounted crafted XFS image. - On success, yields an interactive root shell by executing the SUID bash binary exposed under /tmp/blockdev*/rootbash. No external network C2 or remote URLs/domains are present; the exploit is purely local and relies on system utilities and D-Bus endpoints plus predictable local filesystem paths (/dev/loopN, /tmp/blockdev*).
Repository contains a Bash-based, working local privilege escalation exploit chain for SUSE/openSUSE systems, targeting CVE-2025-6018 (PAM environment variable injection) and CVE-2025-6019 (udisks2/libblockdev XFS resize race). Structure: - README.md: Detailed walkthrough, affected versions, prerequisites, and manual steps to craft an XFS image containing a root-owned SUID payload (typically a copy of the victim’s bash) and to run the exploit in stages (--check/--setup/--exploit/--auto). - create_image.sh: Attacker-side helper (must run as root) that creates a 300MB XFS image, mounts it with loop,suid, copies a provided bash binary to `xpl`, sets owner root:root and mode 4755, verifies permissions, and outputs transfer instructions (scp/gzip). - exploit.sh: Main exploit runner (must be executed as an unprivileged user). Provides modes: * --check: Validates preconditions by grepping /etc/pam.d for pam_env and pam_systemd, checking OS via /etc/os-release, checking udisks2 version, and inspecting polkit policy file `/usr/share/polkit-1/actions/org.freedesktop.UDisks2.policy` for allow_active=yes. * --setup: Implements the CVE-2025-6018 stage by configuring user-controlled PAM environment (via ~/.pam_environment per README) to set XDG_SEAT/XDG_VTNR so that a new login session gains `allow_active` polkit status (requires reconnect and `su - $USER`). * --exploit: Implements the CVE-2025-6019 stage by using udisksctl/gdbus to set up a loop device from the supplied XFS image and trigger an XFS resize operation. During the race window where libblockdev mounts the filesystem without nosuid, it searches `/tmp/blockdev.*/` for the SUID payload `xpl` and executes `xpl -p` to spawn a root shell. Overall capability: reliable LPE to root (root shell) on vulnerable SUSE/openSUSE configurations by chaining a polkit allow_active bypass with a udisks2 XFS mount/race leading to SUID execution.
Repository contains a single Bash proof-of-concept exploit script (exploit.sh) plus a short README with run instructions. The script targets CVE-2025-6019, described as a local privilege escalation via libblockdev/udisks. It provides three modes: (1) create a 300MB XFS image locally (requires root) by dd+mkfs.xfs, mount it, copy /bin/bash into it, and set the SUID bit (chmod 4755); (2) run the target-side exploitation which checks a D-Bus login1 condition (org.freedesktop.login1.Manager.CanReboot returning 'yes') and then uses udisksctl loop device operations (and related temporary files) to trigger the vulnerable behavior using the prepared xfs.image; and (3) a manual, smaller (100MB) XFS image creation workflow. The core capability is delivering a SUID-root bash via a crafted filesystem image and leveraging udisks/libblockdev handling to achieve root-level execution. No external C2/network beacons are present; the only network-related reference is the README’s wget download URL for the script itself.
Repository contains a single POSIX shell script, CVE-2025-6018-19.sh, implementing a two-stage local privilege escalation chain attributed to a Qualys advisory. Structure / modes: - `xfs`: Builds a crafted XFS filesystem image (`./xfs.image`) by zero-filling 300MB, formatting with `mkfs.xfs`, mounting it at `/tmp/xfs.mount`, copying `/bin/bash` into the image, and setting it to setuid-root (owner root:root, mode 4755). The image is then unmounted and made world-readable/writable (chmod 777) for transfer to the target. - `pam`: Writes `~/.pam_environment` with `XDG_SEAT=seat0` and `XDG_VTNR=1`, instructing the user to exit SSH and reauthenticate. This is intended to exploit CVE-2025-6018 to obtain an `allow_active` session context. - `root`: First checks `allow_active` by calling logind over the system D-Bus (`org.freedesktop.login1.Manager.CanReboot`) and grepping for "yes". If not allow_active, it runs `pam` to set up the environment and exits. If allow_active, it kills `gvfs-udisks2-volume-monitor`, sets up a loop device from `./xfs.image` via `udisksctl loop-setup --no-user-interaction`, then triggers a udisks filesystem resize over D-Bus (`org.freedesktop.UDisks2.Filesystem.Resize`). In parallel it polls for `/tmp/blockdev*/bash` to appear, then executes `/tmp/blockdev*/bash -p` to obtain a root shell. Capabilities: - Produces a transferable disk image payload containing a setuid-root shell. - Manipulates PAM environment to influence session/seat variables for privilege/context escalation. - Uses system D-Bus calls to logind and udisks2 to trigger the vulnerable code paths. - Final outcome is a local root shell (setuid bash executed with preserved privileges). No external C2 or network callbacks are present; the only network-like observable is the embedded advisory URL. The exploit is operational but not generalized (hardcoded assumptions like loop0 object path and /tmp/blockdev* location), fitting an OPERATIONAL PoC/LPE script rather than a framework module.
Repository contains a single Bash automation script plus a README describing a chained local privilege escalation against UDisks2/logind D-Bus services on (notably) SUSE/openSUSE environments. Structure & purpose: - `CVE-2025-6018-udisks-lpe-no-image.sh`: Automates the post-CVE-2025-6018 stage of the Qualys-described chain. It assumes the attacker already has the necessary D-Bus permissions/context (obtained by exploiting CVE-2025-6018) and then uses UDisks2 operations to reach a privileged outcome. - `README.md`: Explains that this is not a standalone exploit; it relies on prior exploitation of CVE-2025-6018 and a separately prepared XFS image. Links to the Qualys advisory and an Exploit-DB entry for the prerequisite. Main exploit capabilities (script behavior): 1) Preconditions/validation: checks for `gdbus` and `udisksctl`, and requires a local XFS image `./xfs.image`. 2) D-Bus access check: calls `org.freedesktop.login1.Manager.CanReboot` on the system bus to confirm logind access. 3) Race/condition setup: kills `gvfs-udisks2-volume-monitor` to reduce interference. 4) Loop device setup: uses `udisksctl loop-setup --file ./xfs.image` to create a loop block device (assumes it becomes `loop0`). 5) Privileged artifact wait: polls for `/tmp/blockdev*/bash` for up to 30 seconds, indicating a privileged/SUID bash has been created/bound as part of the chain. 6) Bug trigger: invokes `org.freedesktop.UDisks2.Filesystem.Resize` on `/org/freedesktop/UDisks2/block_devices/loop0` with size `0` to trigger the vulnerable privileged filesystem operation. 7) Payload/action: executes the discovered bash with `-p` to preserve privileges, yielding a root shell, then runs `id`. Overall, this is an operational local LPE helper script for the UDisks2 chain (CVE-2025-6019 per README context) that depends on a prior CVE-2025-6018 step and an externally prepared filesystem image; it does not include image creation or the initial CVE-2025-6018 exploit.
Repository contains a 2-stage local privilege escalation PoC chaining CVE-2025-6018 and CVE-2025-6019 to obtain a root shell on vulnerable Linux systems. Structure (3 files): - README.md: Explains the vulnerability chain and operational steps. Describes creating a malicious XFS image with a SUID root shell, using a Polkit active-session bypass to perform udisks2 operations without authentication, then triggering a udisks2/libblockdev maintenance action that temporarily mounts the filesystem without nosuid, and finally winning a race to execute the SUID payload. - build_poc.sh (attacker-side): Generates artifacts to upload to the target. It (1) compiles a static C SUID shell wrapper (rootbash) that runs /bin/bash -p with setuid(0)/setgid(0); (2) creates a 400MB XFS filesystem image (exploit.img) and injects rootbash with mode 4755; (3) compiles a static C "catcher" that continuously scans /proc/mounts for a /dev/loop mount (excluding /run/media) and immediately executes <mountpoint>/rootbash -p. - exploit.sh (target-side orchestrator): Ensures the session is Active=yes via loginctl; if not, writes ~/.pam_environment with XDG_SEAT=seat0 and XDG_VTNR=1 and instructs the user to re-login. Once active, it starts catcher in the foreground and launches a background trigger script that uses udisksctl loop-setup -f exploit.img to create a loop device, constructs the udisks2 D-Bus object path /org/freedesktop/UDisks2/block_devices/<dev>, and calls gdbus to invoke org.freedesktop.UDisks2.Filesystem.Resize (intended to cause the vulnerable temporary mount). The catcher then attempts to execute the SUID payload during the brief mount window, yielding a root shell. Key capabilities: - Local privilege escalation to root via SUID execution from a temporary mount missing nosuid. - Session-state manipulation for Polkit authorization bypass (writes ~/.pam_environment and relies on loginctl Active=yes). - D-Bus interaction with system udisks2 service to trigger the vulnerable mount behavior. - Race-condition helper (static C) to reliably catch the short-lived mount and execute the payload. Notable observables/endpoints: - Files: ~/.pam_environment, /proc/mounts, /dev/loop*, generated .trigger_bg.sh, exploit.img, catcher. - D-Bus: destination org.freedesktop.UDisks2; object path /org/freedesktop/UDisks2/block_devices/<loopdev>; method org.freedesktop.UDisks2.Filesystem.Resize. - README includes example HTTP transfer endpoints (http://<YOUR_IP>/exploit.img and /catcher) used for staging artifacts.
Repository contains a single bash exploit-chain script and a README. The bash script (ExploitChain.sh) implements a three-stage local privilege escalation chain targeting SUSE/openSUSE systems by combining CVE-2025-6018 (pam_env.so environment injection via ~/.pam_environment and OVERRIDE) with CVE-2025-6019 (UDisks2/libblockdev Filesystem.Resize behavior that can leave a privileged mount behind). Stage 1 (attacker machine, requires root) creates a ~300MB XFS disk image (default ./xfs.image) using tools like dd and mkfs.xfs, and embeds a SUID-root bash inside the filesystem. Stage 2 (target) writes a malicious ~/.pam_environment to poison XDG_* session variables so that after logout/login, systemd-logind/PolicyKit treats the SSH session as ‘active’ (allow_active). Stage 3 (target) interacts with UDisks2 over D-Bus (Filesystem.Resize on a loop device backed by the crafted image) to cause libblockdev to mount the filesystem with exec/suid and fail to unmount on error, leaving the mount accessible under /tmp/blockdev*/; executing the SUID bash yields a root shell. The README documents operator workflow (scp image to /tmp, logout/login, then run stage3) and links to a Qualys write-up. No hardcoded network beacons/C2 are present; network references are limited to example scp/ssh commands and an external advisory URL.
Repository purpose: a local privilege-escalation exploit guide and automation script chaining CVE-2025-6018 and CVE-2025-6019. The repo contains a single exploit script (exp.sh) plus English/Chinese READMEs describing preparation of an attacker-controlled XFS image with a SUID-root bash and the required PAM environment setup. Structure: - exp.sh: Bash exploit executed on the target after a fresh login session. It (1) validates ~/.pam_environment contains XDG_SEAT OVERRIDE=seat0 and XDG_VTNR OVERRIDE=1, (2) checks ~/xfs.image exists, (3) verifies session authorization by calling org.freedesktop.login1.Manager.CanReboot over system D-Bus, (4) kills gvfs-udisks2-volume-monitor, (5) creates a loop device from the XFS image using udisksctl loop-setup, (6) triggers the vulnerable behavior by calling org.freedesktop.UDisks2.Filesystem.Resize on the loop device while a background loop probes /tmp/blockdev*/bash, (7) searches /tmp for a SUID bash and executes it with -p to preserve privileges, confirming euid=0 and spawning an interactive root shell; it also attempts to read /root/root.txt. - README.md and readme_zh-cn.md: Step-by-step instructions to build the XFS image (dd + mkfs.xfs, mount, copy /bin/bash, chmod 4755), upload to target, set PAM env overrides, logout/login, verify CanReboot returns ('yes',), then run exp.sh. They include example SSH/SCP commands and a sample target IP. Exploit capabilities: - Local LPE to root by leveraging system D-Bus interactions with login1 and UDisks2 in a PAM-influenced session. - Uses an attacker-supplied filesystem image to introduce a SUID-root bash and then executes it to obtain a root shell. Notable observables: - D-Bus destinations/methods: org.freedesktop.login1.Manager.CanReboot; org.freedesktop.UDisks2.Filesystem.Resize. - Files/paths: ~/.pam_environment, ~/xfs.image, /dev/loopX, /tmp/blockdev*/bash, /root/root.txt. This is an operational exploit script (not just detection) with a hardcoded privilege-escalation payload (SUID bash) and interactive root shell launch.
Repository contains two Bash scripts implementing an end-to-end exploit chain against a Linux target host. Structure & purpose: - exploit.sh: Attacker-side automation. Installs dependencies (xfsprogs for mkfs.xfs and sshpass) on Arch or Debian/Kali. Logs into the target via SSH using a hardcoded password, writes a ~/.pam_environment file on the target (XDG_SEAT/XDG_VTNR overrides), copies the target's /bin/bash to the attacker, then builds a 300MB XFS filesystem image. It mounts the image locally, places the bash binary inside as 'maul', sets ownership to root:root and permissions to 4755 (SUID), unmounts, and transfers the crafted xfs.image plus privesc.sh to the target via SCP. - privesc.sh: Target-side privilege escalation helper. Kills gvfs-udisks2-volume-monitor, sets up a loop device for xfs.image using udisksctl, then uses a system D-Bus call to org.freedesktop.UDisks2.Filesystem.Resize on loop0. It repeatedly attempts to execute /tmp/blockdev*/maul (the SUID bash from the mounted image) and finally runs '/tmp/blockdev*/maul -p' to preserve elevated privileges, yielding a root shell. Exploit capabilities: - Remote access: Uses SSH/SCP with sshpass and hardcoded credentials to interact with the target and transfer files. - Payload delivery: Crafts an XFS image containing a SUID-root bash binary. - Privilege escalation: Leverages UDisks2/gvfs/loop-device handling and a D-Bus Filesystem.Resize call to make the attacker-controlled filesystem content available under /tmp/blockdev* and execute the SUID payload for root. Notable observables: - Target host: pterodactyl.htb; user: phileasfogg3; hardcoded password: '!QAZ2wsx'. - Key local/remote artifacts: /tmp/xfs.image, /tmp/maul, /tmp/blockdev*/maul, and target-side ~/.pam_environment and ~/xfs.image, ~/privesc.sh.
This repository contains a Python exploit (CVE-2025-6018.py) targeting a local privilege escalation vulnerability in Linux PAM (Pluggable Authentication Modules) affecting versions 1.3.0 to 1.6.0, particularly on openSUSE Leap 15 and SUSE Linux Enterprise 15. The exploit leverages SSH (via paramiko) to connect to a target system, checks for vulnerable PAM configurations, and injects crafted environment variables into the user's ~/.pam_environment file. If pam_env.so is loaded before pam_systemd.so, this allows the attacker to impersonate a local/active user, gaining elevated Polkit privileges (allow_active). The exploit can be chained with CVE-2025-6019 for full root access. The repository consists of the main exploit script and a README.md with detailed technical and mitigation information. The attack requires local or SSH access and exploits file-based configuration endpoints. The exploit is operational, providing a working privilege escalation chain for vulnerable systems.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-6019, a local privilege escalation vulnerability in UDisks2 on Linux (tested on Ubuntu 20.04.6). The exploit demonstrates how a local attacker can craft a malicious XFS filesystem image containing a SUID-root binary (check_root), mount it via a loop device, and trigger a D-Bus call to UDisks2 to resize the filesystem. This process bypasses certain safety flags, allowing the SUID binary to be executed with root privileges. The repository contains a C program (check_root.c) that serves as the SUID payload, a Bash script (exploit_helper.sh) to automate the mounting and execution process, and detailed step-by-step instructions in the README.md. The exploit is educational and non-destructive, focusing on privilege escalation demonstration rather than causing harm. No network endpoints are involved; all actions are performed locally on the target system.
This repository provides a comprehensive proof-of-concept (PoC) for CVE-2025-6019, a local privilege escalation vulnerability in the libblockdev library as used by udisks2 on Linux systems. The exploit leverages the fact that udisks2 may mount user-supplied XFS images without the 'nosuid' flag, allowing a SUID-root shell embedded in the image to be executed with root privileges. The repository is structured as follows: - Documentation files (README.md, Check_Guide.md, Lab_Setup_Guide.md, POC_Guide.md) provide detailed background, affected versions, and step-by-step instructions for both setting up a vulnerable environment and executing the exploit. - The 'poc-lab/Dockerfile' automates the creation of a vulnerable Ubuntu 22.04 environment with the necessary tools and a non-privileged user for testing. - The PoC process involves compiling a simple C program that spawns a root shell, embedding it into a malicious XFS image, and using udisksctl to mount the image via D-Bus, exploiting the vulnerability to gain root access. No network endpoints or remote attack vectors are present; the exploit is strictly local and requires the attacker to have access to the target system. The repository does not contain a ready-made exploit script, but provides all the steps and code necessary to reproduce the attack in a controlled environment. The main exploit capability is local privilege escalation to root on affected Linux distributions.
This repository contains a proof-of-concept (PoC) local privilege escalation (LPE) exploit for CVE-2025-6019, targeting Linux systems using vulnerable versions of libblockdev/udisks. The exploit is implemented in two bash scripts: 'attacker.sh' and 'target.sh'. 'attacker.sh' is used to create a specially crafted 300 MB XFS filesystem image containing a SUID bash binary. This script must be run as root to create and prepare the image. The image is then transferred to the target system. 'target.sh' is executed on the target system (as a regular user) to exploit the vulnerability. It sets up a loop device with the malicious XFS image, interacts with the udisks2 service via D-Bus (using gdbus), and triggers a filesystem resize operation. This process results in the XFS image being mounted with the SUID bash binary in '/tmp/blockdev*/bash'. The script then executes this SUID bash with the '-p' flag, providing a root shell to the attacker. The exploit requires the ability to transfer files to the target and execute scripts. It leverages local attack vectors and does not require network access. The main fingerprintable endpoints are the XFS image file, the mount point, the SUID bash binary in /tmp, and the use of loop devices. The repository is structured as a straightforward PoC, with clear separation between the image creation (attacker) and exploitation (target) phases.
This repository provides a two-stage local privilege escalation exploit targeting Linux systems with UDisks2 and XFS support, referencing CVE-2025-6019. The exploit consists of two bash scripts: 1. `1.sh` creates a 300MB XFS image, mounts it, copies `/bin/bash` as a SUID root shell (`root-shell`) into the image, and then unmounts it. This prepares a malicious filesystem image. 2. `2.sh` is run on the target system. It sets up a loop device for the crafted XFS image using `udisksctl`, then attempts to trigger a vulnerability in UDisks2 by calling the `Filesystem.Resize` method via D-Bus. The script then searches `/tmp` for the SUID `root-shell` binary, and if found, executes it with the `-p` flag to obtain a root shell. The README provides usage instructions and a demonstration of successful privilege escalation. The exploit is operational, providing a working SUID shell payload, and is not part of any known exploit framework. The main attack vector is local, requiring the attacker to execute scripts on the target system. Several file system endpoints are involved, including the crafted XFS image and temporary directories used for mounting and searching for the SUID shell.
This repository contains a proof-of-concept (PoC) local privilege escalation exploit for CVE-2025-6019, targeting a race condition in the udisks2 service on Linux. The exploit consists of a Bash script ('exploit.sh') and a README.md with detailed usage instructions and background. The exploit works in two stages: first, it creates a crafted XFS image containing a SUID-root bash binary; second, it uses udisks2's DBus interface to mount this image in a temporary directory under /tmp (e.g., /tmp/blockdev*), exploiting a race condition during the filesystem resize operation. If successful, the SUID-root shell can be executed from this temporary directory, granting root access. The exploit requires local access from an active, non-remote logind session and will not work over SSH or remote sessions unless polkit rules are modified. The repository is structured simply, with the main exploit logic in 'exploit.sh' and comprehensive documentation in 'README.md'.
This repository provides a Proof of Concept (PoC) exploit for CVE-2025-6019, a local privilege escalation vulnerability in the Linux udisks2/libblockdev stack. The repository contains three files: a detailed README.md, a demo SVG image, and the main exploit script (exploit.sh). The exploit works in two stages: (1) it creates a 300 MB XFS filesystem image containing a SUID bash binary (requires root), and (2) it transfers this image to a target system and uses udisks2/libblockdev to mount it without the nosuid option, allowing execution of the SUID bash and thus obtaining a root shell. The script includes robust error handling, dependency checks, and cleanup routines. The attack is purely local and requires the attacker to have access to the target system to execute the script and transfer files. The exploit targets Linux systems with vulnerable versions of udisks2/libblockdev, specifically tested on openSUSE Leap 15.6 and Kali GNU/Linux Rolling 2023.4, but may work on other distributions. No network endpoints are involved; all actions are performed via local file and device manipulation.
64 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A locally exploitable vulnerability affecting Rocky Linux 8.6, addressed by CIQ security advisory CIQSA-2026:0071. It has a CVSS v3 vector of AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating high impact to confidentiality, integrity, and availability after exploitation.
A local privilege escalation flaw enabling escalation from allow_active to root on affected Linux distributions (per the content).
A previously disclosed similar UDisks vulnerability referenced only as part of vendor security history.
A critical software vulnerability listed as a trending CVE for the week. Specifics not detailed in the content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.