Two New Linux Vulnerabilities Open the Door to Root Access Attacks

Listen to this Post

Featured Image

Introduction: A New Wave of Linux Security Threats

Linux, often seen as the bastion of open-source security, is facing serious threats with the discovery of two local privilege escalation (LPE) vulnerabilities. These flaws, uncovered by Qualys researchers, expose machines running popular Linux distributions to potential full system takeover by malicious users. The issues specifically exploit weaknesses in SUSE’s PAM system and the libblockdev framework via the udisks daemon, making almost every major Linux system susceptible to attack. With privilege escalation serving as a key tool for attackers to gain unauthorized access, this discovery raises red flags across the cybersecurity landscape.

the Original Discovery

Cybersecurity firm Qualys has identified two major local privilege escalation (LPE) flaws that impact key Linux systems. These vulnerabilities are:

CVE-2025-6018 – This flaw affects the Pluggable Authentication Modules (PAM) in SUSE Linux Enterprise 15 and openSUSE Leap 15. It allows an unprivileged local user to elevate to the “allow_active” level, enabling them to initiate Polkit actions typically restricted to physically present users.
CVE-2025-6019 – This second vulnerability affects the libblockdev component, particularly via the widely deployed udisks daemon. When chained with CVE-2025-6018, it enables a local attacker to escalate from “allow_active” to full root privileges.

According to Qualys, these vulnerabilities collapse the traditional security boundary between a standard logged-in user and the system’s highest privilege level: root. By exploiting the trust zone of polkit and leveraging weaknesses in PAM/environment interactions, attackers can escalate privileges rapidly, even from remote GUI or SSH sessions.

These flaws are particularly dangerous because the udisks service is included by default in nearly all major Linux distributions—including Ubuntu, Debian, Fedora, and openSUSE. The ease of access to “allow_active” privileges, combined with the ubiquity of the affected components, means that millions of Linux systems could be vulnerable.

Adding to the list of concerns, a third high-severity vulnerability (CVE-2025-6020) was also disclosed in Linux PAM. This path traversal issue in the pam_namespace module could allow local users to escalate privileges via race conditions and symlink attacks. The flaw has been addressed in version 1.7.1.

To mitigate these threats, Linux users and administrators are strongly advised to apply vendor patches immediately. Temporary workarounds include modifying Polkit rules to enforce administrative authentication and disabling vulnerable PAM modules or restricting user-controlled paths.

What Undercode Say: 🛡️ Deep Dive into the Threat Landscape

Understanding the Technical Impact

These vulnerabilities are a masterclass in chaining legitimate system services for malicious gain. By leveraging standard components such as PAM and udisks, attackers sidestep the need for complex remote code execution exploits. This trend emphasizes that post-authentication threats can be just as dangerous, if not more, than pre-authentication attacks.

PAM and Polkit: A Risky Trust Model

PAM modules have long been trusted to manage user sessions and authentication. However, in this case, the trust boundaries are misconfigured, especially concerning the “allow_active” session privilege. Polkit was designed to respect physical presence as a prerequisite for executing sensitive actions—but these flaws break that model entirely. Undercode notes this breach undermines a key tenant of Linux’s layered security design.

Why Chaining is Dangerous

The real threat isn’t just one flaw—it’s the way these vulnerabilities interact. Exploiting CVE-2025-6018 to get “allow_active” access and then CVE-2025-6019 to gain root is alarmingly efficient. It’s a textbook example of privilege escalation chaining, which is much harder to detect and defend against.

Attack Surface: More Than Just SUSE

While SUSE is directly affected by the PAM issue, the underlying mechanics of udisks and libblockdev mean that virtually any Linux system running these services is exposed. Ubuntu, Fedora, Debian, and their derivatives all include these by default, meaning enterprise environments and even personal desktops are at risk.

Real-World Exploitability

Qualys has developed PoC exploits and successfully tested them on major distributions, proving the viability of these attacks in real-world scenarios. This isn’t just a theoretical vulnerability—it’s operational.

Patch Management Challenges

The biggest challenge now is timely patch deployment. Enterprise systems often delay updates due to stability concerns, leaving a large attack window. Even worse, some administrators might not understand the severity if they believe “local user access” limits the impact.

The Role of Default Configurations

The danger here also lies in default trust settings. With udisks installed by default and Polkit not always hardened, systems are vulnerable out-of-the-box. Undercode stresses the importance of hardening default installations and not assuming that user-access equates to safety.

Insider Threats Amplified

Since the exploit requires local access, it elevates the danger from insiders or compromised user accounts. Once inside, attackers can quickly leapfrog to root access and implant persistent malware, such as rootkits or remote shells.

Mitigation Is Possible—But Needs Action

Short-term mitigation steps like modifying Polkit rules and disabling vulnerable PAM features are available, but the real solution lies in system-wide patching. Organizations must integrate faster update cycles and security-first configuration practices.

✅ Fact Checker Results

✅ Fact: The two LPE vulnerabilities (CVE-2025-6018 and CVE-2025-6019) are confirmed by Qualys and tested across major Linux distributions.
✅ Fact: The udisks daemon is installed by default on most Linux systems, significantly increasing the attack surface.
❌ Misinformation: Not all Linux systems are patched automatically—manual intervention is often required to mitigate the risks.

🔮 Prediction: What Comes Next for Linux Security?

The rise of local-to-root privilege escalation exploits like these signals a paradigm shift in Linux threat modeling. Attackers are moving away from complex remote exploits and focusing on user-level compromises followed by rapid privilege escalation. Future threats will likely exploit similar trust zones within core Linux components, emphasizing the need for proactive hardening, zero-trust models, and stricter session privilege enforcement. We predict that PAM and Polkit will face increased scrutiny and undergo major architectural reviews in upcoming distributions.

References:

Reported By: thehackernews.com
Extra Source Hub:
https://www.pinterest.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram