CVE-2025-6019General

LOWCVSS 7.0 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. However, a local attacker can create a specially crafted XFS image containing a SUID-root shell, then trick udisks into resizing it. This mounts their malicious filesystem with root privileges, allowing them to execute their SUID-root shell and gain complete control of the system.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-02-08); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1Mentions · 2026-02-12: 1Mentions · 2026-02-15: 1Mentions · 2026-05-16: 1PoC Mentioned / Linked · 2026-02-09: 1PoC Mentioned / Linked · 2026-05-16: 1Exploit Tool / Code · 2026-02-09: 1Exploit Tool / Code · 2026-05-16: 1Technical Details · 2026-02-09: 1Technical Details · 2026-05-16: 102-0802-0902-1202-1505-16
Signal classification4 categories
General
240.0%
PoC
120.0%
Disclosure
120.0%
Exploit
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-081
General1
2026-02-091
PoC1
2026-02-121
General1
2026-02-151
Disclosure1
2026-05-161
Exploit1
Full discourse5 posts
  • DFIR Radar@DFIR_Radar
    Exploit

    Critical directory traversal in Pterodactyl Panel v1.11.10 leads to unauthenticated RCE via PHP-PEAR exploitation chain. CVE-2025-49132 combines with PEAR pearcmd technique enabling arbitrary webshell deployment. Key technical details: • Endpoint /locales/locale.json bypasses auth middleware, accepts unsanitized locale/namespace parameters • Path traversal: locale=../../../../../usr/share/php/PEAR&namespace=pearcmd enables arbitrary .php file inclusion • PEAR pearcmd.php accepts config-create command via register_argc_argv, writes attacker-controlled content to disk • Payload: `<?=system($_REQUEST[0]);?>` creates webshell at /tmp/shell.php accessible via LFI Attack chain methodology: • Initial recon reveals Pterodactyl Panel v1.11.10 with PHP-PEAR enabled • Directory traversal to include pearcmd.php with malicious config creation • Second request includes written webshell for command execution • Database credential extraction leads to bcrypt hash cracking: !QAZ2wsx • Privilege escalation via CVE-2025-6018 (PAM environment bypass) + CVE-2025-6019 (libblockdev/udisks XFS mounting) Hunt for HTTP requests to `/locales/locale.json` with `../` sequences in locale parameter and suspicious namespace values targeting pearcmd.php. #DFIR_Radar

    Post summary

    The entry details a full exploitation chain for CVE‑2025‑49132, including PoC code, traversal vector, and post‑exploit actions, classifying it as an exploit.

    110221.8K
    1.8K followersView on X
  • IT Cat ✈️@itcaat
    General

    @gaxeliy @Wandrovik Также уязвимости Linux (я что вам какая то шутка ) CVE-2025-38561, CVE-2025-6018, CVE-2025-6019, CVE-2025-32463, CVE-2026-24061

    Post summary

    The tweet lists several Linux CVE identifiers but offers no additional context, technical details, or actionable information.

    1001049
    1.5K followersView on X
  • Michael Venturella@Mr_Venturella
    PoC

    Created my first CVE exploit for CVE-2025-6018 &amp; CVE-2025-6019: Local Privilege Escalation. Check it out here on github https://github.com/MichaelVenturella/CVE-2025-6018-6019-PoC

    Post summary

    User posted a proof‑of‑concept exploit on GitHub for CVE‑2025‑6018 and CVE‑2025‑6019, which are local privilege escalation vulnerabilities.

    0001097
    15 followersView on X
  • Brian_Bundi@bundibrianx
    General

    Just finished a deep dive into Pterodactyl on HackTheBox. This one was a beast—chaining CVE-2025-49132 for the initial foothold, then navigating PAM environment injection (CVE-2025-6018) and a UDisks2 LPE (CVE-2025-6019) to hit root. https://labs.hackthebox.com/achievement/machine/2252974/832 #HackTheBox #HTB

    Post summary

    The statement notes chaining of three CVEs during a HackTheBox lab exercise, without providing additional details on exploitation, patches, or real-world usage.

    0001078
    2 followersView on X
  • KOREONE42@KOREONE42
    Disclosure

    root through udisks flaw -&gt; CVE-2025-6019 https://www.bleepingcomputer.com/news/linux/new-linux-udisks-flaw-lets-attackers-get-root-on-major-linux-distros/ https://t.co/OQsI6MIgro

    Post summary

    The tweet points to a new udisks flaw (CVE‑2025‑6019) that could grant root access on major Linux distributions, but it provides no detailed technical information or exploit evidence.

    0000054
    70 followersView on X

Explore more