Skip to main content Skip to local navigation

Linux Vulnerability (CVE-2025-6019)

 

A picture containing text  Description automatically generated

 

Service Advisory 


A recently discovered Local Privilege Escalation (LPE) vulnerability (CVE-2025-6019) enables attackers to gain root privileges on most Linux distributions.

Severity level: 
CVSS Score: 7/High

Description:
The libblockdev library is used for low-level operations with block devices (e.g., hard disks) in Linux. The CVE-2025-6019 vulnerability is exploited by accessing the udisks2 daemon (used to manage storage devices) — provided that the attackers manage to obtain the privileges of the active user present on the computer (allow_active).

Affected Versions:
Linux distributions

                         

Impact:
Successful exploitation could allow unauthorized access to the systems.

 

Resolution:
Appy the patches released by the vendors.

Reference:

https://nvd.nist.gov/vuln/detail/CVE-2025-6019

https://ubuntu.com/security/CVE-2025-6019

https://access.redhat.com/security/cve/CVE-2025-6019

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6019

 

UIT Information Security

Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

PRIVACY POLICY | VISIT WWW.YORKU.CA
This email was sent by: York University, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web