Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:02043-1

Опубликовано: 20 июн. 2025
Источник: suse-cvrf

Описание

Security update for libblockdev

This update for libblockdev fixes the following issues:

  • CVE-2025-6019: Suppress privilege escalation during xfs fs resize (bsc#1243285).

Список пакетов

SUSE Enterprise Storage 7.1
libbd_crypto2-2.22-150200.3.3.1
libbd_fs2-2.22-150200.3.3.1
libbd_loop2-2.22-150200.3.3.1
libbd_mdraid2-2.22-150200.3.3.1
libbd_part2-2.22-150200.3.3.1
libbd_swap2-2.22-150200.3.3.1
libbd_utils2-2.22-150200.3.3.1
libblockdev-2.22-150200.3.3.1
libblockdev2-2.22-150200.3.3.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
libbd_crypto2-2.22-150200.3.3.1
libbd_fs2-2.22-150200.3.3.1
libbd_loop2-2.22-150200.3.3.1
libbd_mdraid2-2.22-150200.3.3.1
libbd_part2-2.22-150200.3.3.1
libbd_swap2-2.22-150200.3.3.1
libbd_utils2-2.22-150200.3.3.1
libblockdev-2.22-150200.3.3.1
libblockdev2-2.22-150200.3.3.1
SUSE Linux Enterprise Server 15 SP3-LTSS
libbd_crypto2-2.22-150200.3.3.1
libbd_fs2-2.22-150200.3.3.1
libbd_loop2-2.22-150200.3.3.1
libbd_mdraid2-2.22-150200.3.3.1
libbd_part2-2.22-150200.3.3.1
libbd_swap2-2.22-150200.3.3.1
libbd_utils2-2.22-150200.3.3.1
libblockdev-2.22-150200.3.3.1
libblockdev2-2.22-150200.3.3.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
libbd_crypto2-2.22-150200.3.3.1
libbd_fs2-2.22-150200.3.3.1
libbd_loop2-2.22-150200.3.3.1
libbd_mdraid2-2.22-150200.3.3.1
libbd_part2-2.22-150200.3.3.1
libbd_swap2-2.22-150200.3.3.1
libbd_utils2-2.22-150200.3.3.1
libblockdev-2.22-150200.3.3.1
libblockdev2-2.22-150200.3.3.1

Описание

A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. However, a local attacker can create a specially crafted XFS image containing a SUID-root shell, then trick udisks into resizing it. This mounts their malicious filesystem with root privileges, allowing them to execute their SUID-root shell and gain complete control of the system.


Затронутые продукты
SUSE Enterprise Storage 7.1:libbd_crypto2-2.22-150200.3.3.1
SUSE Enterprise Storage 7.1:libbd_fs2-2.22-150200.3.3.1
SUSE Enterprise Storage 7.1:libbd_loop2-2.22-150200.3.3.1
SUSE Enterprise Storage 7.1:libbd_mdraid2-2.22-150200.3.3.1

Ссылки
Уязвимость SUSE-SU-2025:02043-1