# Call for testing - libblockdev CVE-2025-6019 Local Privilege Escalation Vulnerability

DevFeed: [Call for testing - libblockdev CVE-2025-6019 Local Privilege Escalation Vulnerability](<https://devfeed.tech/articles/call-for-testing-libblockdev-cve-2025-6019-local-privilege-escalation-vulnerability-53419.md>)

Original publisher: [Read original article](<https://almalinux.org/blog/2025-06-18-test-patches-for-cve-2025-6019/>)

Author: Jonathan Wright Infrastructure SIG lead; ALESCo member

Published: 2025-06-18T00:00:00Z

Content type: release

Language: en

Sources: [AlmaLinux](<https://devfeed.tech/sources/blog-on-almalinux.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [patches](<https://devfeed.tech/topics/patches.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [linux](<https://devfeed.tech/tags/linux.md>), [local-privilege-escalation](<https://devfeed.tech/tags/local-privilege-escalation.md>), [operating-system](<https://devfeed.tech/tags/operating-system.md>), [patches](<https://devfeed.tech/tags/patches.md>), [patching](<https://devfeed.tech/tags/patching.md>), [privilege-escalation](<https://devfeed.tech/tags/privilege-escalation.md>), [test](<https://devfeed.tech/tags/test.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

AlmaLinux is affected by CVE-2025-6019, a libblockdev vulnerability exploitable through the udisks daemon to obtain root privileges. The article asks users to test patched libblockdev packages and provides installation and verification steps for AlmaLinux versions 8, 9, 10, and Kitten 10.

## Source excerpt

Yesterday, Qualys published details about a vulnerability discovered in the libblockdev package. Two vulnerabilities were announced, CVE-2025-6018 and CVE-2025-6019. AlmaLinux is not impacted by CVE-2025-6018, but we are impacted by CVE-2025-6019. Without the impact of CVE-2025-6018 the vulnerability in libblockdev (CVE-2025-6019) is arguably less critical, but it is impactful nonetheless. The second (CVE-2025-6019) affects libblockdev, is exploitable via the udisks daemon included by default on most Linux distributions, and allows an "allow_active" user to gain full root privileges. Although CVE-2025-6019 on its own requires existing allow_active context, chaining it with CVE-2025-6018 enables a purely unprivileged attacker to achieve full root access.