CVE-2025-8067 is an out-of-bounds read vulnerability in the UDisks (udisks2) daemon's D-Bus loop-device setup handler. The handler accepts a file-descriptor list and an index identifying the descriptor for the loop device backing file. Although it enforces an upper bound on the index, it does not reject negative values. An unprivileged local user can submit a crafted D-Bus LoopSetup request with a negative file-descriptor index, causing the daemon to access memory outside the descriptor list. The resulting value may be treated as an open daemon file descriptor and mapped to a loop device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains two Python proof-of-concept (PoC) exploits targeting CVE-2025-8067, a vulnerability in the Udisks daemon (org.freedesktop.UDisks2) on Linux systems. The first script, 'poc.py', demonstrates a denial-of-service (DoS) attack by sending an out-of-bounds index to the 'LoopSetup' D-Bus method, causing the daemon to crash. The second, more advanced script, 'poc-fd-steal.py', iterates over negative indices to 'steal' an open file descriptor from the daemon, mounting it as a loop device and revealing the backing file, which could expose sensitive information. Both scripts use the Python GObject Introspection bindings to interact with the system D-Bus and require the vulnerable Udisks daemon to be running. The repository is structured with a README providing references and two PoC scripts, each demonstrating a different aspect of the vulnerability. No network endpoints are involved; the attack vector is local, leveraging D-Bus IPC mechanisms.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An out-of-bounds read vulnerability in the UDisks daemon (udisks) affecting Rocky Linux 9 packages covered by CIQ advisory crlsa-2025_15018.
Unknown (listed as a trending CVE for Linux UDisks daemon without details in the content).
An out-of-bounds read vulnerability in the UDisks daemon's loop device handler that can be triggered via the D-BUS interface by supplying a negative index, allowing local denial of service and potentially local privilege escalation.
A high-severity local vulnerability in the UDisks (udisks2) daemon where insufficient lower-bound validation of a D-Bus method argument (fd_index) causes an out-of-bounds read in GLib’s GUnixFDList access path, enabling denial of service and potentially local privilege escalation by exposing/reusing an internal daemon file descriptor via loop device setup.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.