{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/libblockdev/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:suse:pam-config:1.1.8-24.71.1:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2025-6018"},{"cvss":7,"id":"CVE-2025-6019"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pam-config","pam_env.so","UDisks2","libblockdev"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["SUSE"],"content_html":"\u003cp\u003ePublicly available proof-of-concept exploits describe a multi-stage local privilege escalation (LPE) chain targeting SUSE and openSUSE distributions. The attack leverages CVE-2025-6018 and CVE-2025-6019 to elevate an unprivileged user to root. The first stage involves exploiting an environment variable injection vulnerability in the PAM module \u003ccode\u003epam_env.so\u003c/code\u003e (CVE-2025-6018). By injecting specific directives into \u003ccode\u003e~/.pam_environment\u003c/code\u003e, an attacker can manipulate XDG session variables to deceive \u003ccode\u003esystemd-logind\u003c/code\u003e into incorrectly granting 'allow_active' PolicyKit privileges.\u003c/p\u003e\n\u003cp\u003eOnce the attacker gains these elevated permissions, they exploit a race condition in UDisks2 and \u003ccode\u003elibblockdev\u003c/code\u003e (CVE-2025-6019). This vulnerability occurs during the \u003ccode\u003eFilesystem.Resize\u003c/code\u003e D-Bus method call, where an attacker can mount a malicious XFS filesystem image containing a SUID root binary. Because the system fails to unmount the filesystem properly after a triggered error, the SUID binary becomes accessible in a temporary directory, allowing the attacker to execute it and obtain a root shell.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker prepares a 300MB XFS filesystem image containing a SUID root bash binary on a local system.\u003c/li\u003e\n\u003cli\u003eAttacker transfers the malicious filesystem image to the target SUSE system, typically placing it in \u003ccode\u003e/tmp/\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the local \u003ccode\u003e~/.pam_environment\u003c/code\u003e file on the target to include malicious XDG session variables (e.g., XDG_SEAT, XDG_VTNR).\u003c/li\u003e\n\u003cli\u003eAttacker triggers the PAM injection by logging out and logging back into the target system via SSH.\u003c/li\u003e\n\u003cli\u003eThe target's \u003ccode\u003esystemd-logind\u003c/code\u003e processes the malicious environment, elevating the attacker's session status to 'allow_active' within PolicyKit.\u003c/li\u003e\n\u003cli\u003eAttacker initiates the \u003ccode\u003eFilesystem.Resize\u003c/code\u003e method via D-Bus, targeting the previously uploaded XFS image.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003elibblockdev\u003c/code\u003e component mounts the image but fails to unmount it after the resize operation errors out, leaving the files accessible in \u003ccode\u003e/tmp/blockdev*/\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker executes the SUID root bash binary found in the temporary mount point to gain root privileges.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full local privilege escalation, granting an attacker root access on affected SUSE and openSUSE systems. This allows for total system compromise, data exfiltration, and persistence, provided the attacker has already obtained an initial unprivileged user session.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize patching SUSE and openSUSE systems by applying official updates that address CVE-2025-6018 and CVE-2025-6019.\u003c/li\u003e\n\u003cli\u003eMonitor systems for suspicious creation of \u003ccode\u003e~/.pam_environment\u003c/code\u003e files, particularly those containing XDG variable overrides.\u003c/li\u003e\n\u003cli\u003eAudit PolicyKit configuration and limit 'allow_active' permissions for standard, non-interactive service accounts.\u003c/li\u003e\n\u003cli\u003eUse File Integrity Monitoring (FIM) to detect the presence of SUID binaries in temporary directories like \u003ccode\u003e/tmp/\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T09:03:38Z","date_published":"2026-08-26T09:03:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-suse-lpe-chain/","summary":"An exploit chain targeting SUSE Linux systems leverages CVE-2025-6018 and CVE-2025-6019 to achieve local privilege escalation to root by abusing PAM environment injection and a race condition in UDisks2.","title":"Local Privilege Escalation Chain on SUSE Linux via CVE-2025-6018 and CVE-2025-6019","url":"https://feed.craftedsignal.io/briefs/2026-08-suse-lpe-chain/"}],"language":"en","title":"CraftedSignal Threat Feed - Libblockdev","version":"https://jsonfeed.org/version/1.1"}