Database/Kernel, userspace & hypervisor
libblockdev / udisks: allow_active to root via libblockdev through udisks
CVSS 7.0CVE-2025-6019Kernel, userspace & hypervisorcurated
Impact
allow_active to root via libblockdev through udisks - second half of the chain, works on nearly every mainstream distro
Who can reach it
Local user
What to do
Package update + restart udisksd; no reboot
References
Related entries
- Linux kernel (arch/x86/kernel/fpu): A guest that disables an XSAVE feature through XFD while the saved XSTATE_BV stillCVE-2026-23005 · Linux kernel (arch/x86/kernel/fpu)High
- Linux kernel (net/rds): RDS always programs the masked variants of the RDMA atomic opcodes, but the send-completionCVE-2026-52939 · Linux kernel (net/rds)High
- Linux kernel (drivers/pci): An SR-IOV device that stops answering config reads makes the VF Resizable BAR restore pathCVE-2026-64460 · Linux kernel (drivers/pci)High
- Windows Server Services for NFS: use-after-free in the ONCRPC XDR driver gives local code executionCVE-2026-70585 · Windows Server Services for NFS (ONCRPC XDR kernel driver)High
- Linux kernel BPF verifier: JMP32 comparisons against zero mispredicted, allowing unsafe pointer arithmeticCVE-2026-98041 · Linux kernel BPF verifier (is_branch_taken, JMP32 pointer-vs-zero prediction)High
- Linux kernel BPF: per-CPU map updates accept invalid CPU IDs on sparse CPU masks, corrupting kernel memoryCVE-2026-98150 · Linux kernel BPF (BPF_F_CPU target-CPU validation in bpf_map_check_op_flags)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.