Qualys ืืื ืืืืขื ืืืคืืฆืืจื ื ืฉืืืืืงืืื (CVE-2025-6019) ืืื ืืขืจ libblockdev ืืืืืืืืขืง ืืืืก ืขืจืืืืื ืจืื ืคืจืืืืืืขืืืขืก ืฆื ืืืขืจื ืืืงืืืขื ืืืจื ืืื ืืคืืืืจื ืืขื udisks ืืื ืืขืจืืจืื ื ืคืจืืฆืขืก. ื ืคืจืืืืืืค ืขืงืกืคืืืื ืืื ืืขืืื ืกืืจืืจื ืืขืืืืจื ืืื Ubuntu, Debian, ืคืขืืึธืจืึท ืืื openSUSE ืืืคึผ 15.
ืืขืจ udisks ืคึผืจืึธืฆืขืก ืืืขืจื ืืขื ืืฆื ืืื ืึผืืขื ืึทืืข ืืืกืืจืืืืืฉืึทื ื. Linux ืืื ืืื ื ืื-ืืืก ืืื ืืขืจืคืืืก ืคืืจื ืืืจืืคืืจื ืกืืึธืจืืืืฉ ืืคืขืจืืฆืืขืก, ืืื ืืืฉื ืืึธืื ืืื ื ืืื ืคึฟืึธืจืืึทืืื ื. ืฆื ืืืจืืคืืจื ืกืืึธืจืืืืฉ ืืคืขืจืืฆืืขืก, ืจืืคื udisks libblockdev ืืืืืืึธืืขืง ืคืื ืงืฆืืขืก. ืืืจื ืคืขืืืงืืื, ืืื ืฆืืืจืื ืฆื udisks ื ืึธืจ ืื ืืืฆื ืคืืจ ืืึทื ืืฆืขืจ ืืืึธืก ืืืืคื ืืื ืืขื "allow_active" ืงืึธื ืืขืงืกื, ื.ื., ืืขื ืข ืืื ืคืืืืฉื ืฆืืืจืื ืฆืื ืงืึธืืคึผืืืืขืจ ืืื ืคืืจืืื ืื ืืืจื ืึท ืืึธืงืึทืืข ืงืึทื ืกืึธืื ืึธืืขืจ ืืจืึทืคึฟืืฉืข ืกืขืกืืข. ืืึทื ืืฆืขืจ ืืืึธืก ืคืึทืจืืื ืื ืืื ืืืืืื ืก, ืืืฉื ืืืจื SSH, ืืืขืจื ื ืืฉื ืฆืืืขืืืืื ืฆื ืืขื ืงืึธื ืืขืงืกื ืืื ืงืขื ืขื ื ืืฉื ืืืืื ืืืืกื ืืฆื ืื ืืืึทืื ืขืจืึทืืืืืื.
ืืื ืฆื ืืืืืืื ืื ืืืืจืขื ืขืฆืื ื, ืงืขื ื ืืืจ ื ืืฆื ื ืืจืืง ืืืืก ืขืจืืืืื ืืืื ืฆื ืืืืื ืืขื ืืืืืขื ืืืคืืงืืฆืืข ืืขืืืขื ืฆื "allow_active" ืืืจื ืืื ืืคืืืืจื ืืขื ืืื ืืฉ ืคืื ืขื ืืื ืืฆืขืจ ืกืขืจืืืืก ืืืจื ืืขื systemctl ืืืืืืืื, ืืืืก polkitd ืืืขื ืืืืขืจืงื ืืืก ื ืกืืื ืคืื ื ืืืงืืืขืจ ืกืขืกืืข. ืื ืขืกืขื ืฅ ืคืื ืืขืจ ืืขืืื ืืื ืื polkitd ืืืฉืืืื ืื ืื ืืืขืื ืืืื ืคืื ืคืืืืฉื ืฆืืืจืื ืืื ืืืฉืืืื ืืขื "allow_active" ืืขืืืขื ืืืืืจื ืืืืฃ ืืืืืืจืขืงืืข ืกืืื ืื ืืืืก ืงืขื ืขื ืืืขืจื ืืืืืื ืคืืืกื. ืื ืืืืจืขื ืขืฆืื ืืขื ืคืื ืืขืจ ืืขืืื ืืขื ืขื ืื ืืื ืฆื ืคืืจืคืืจื polkitd, ืืื ืขืก ื ืืืืื ืื ื ืืืงืืืข ืืื ืืฆืขืจ ืกืขืกืืข ืืื ืคืืืืฉื ืฆืืืจืื ืืื ืฉืืื ืืืื ืืงืืืื ืืื ืกืืกืืขื.
ืื ืฆืืืืืืข ืืขืืึธืืข ืคึฟืึทืจ ืืึทืงืืืขื "allow_active" ืคึผืจืืืืืืขืืืขืก ืืื ืฆื ื ืืฆื ืึท ืฉืืืึทืืงืืื (CVE-2025-6018) ืืื PAM (Pluggable Authentication Modules), ืืืึธืก Qualys ืคึฟืึธืจืฉืขืจ ืืึธืื ืึทื ืืืขืงื ืืขืช ืืืืขืจ ืึทื ืึทืืื ืคึฟืื ืึท ืฉืืืึทืืงืืื ืืื libblockdev. ืื ืฉืืืึทืืงืืื ืืขืจืืืืื ืืขืื ืืึทื ืืฆืขืจ, ืึทืจืืึทื ืืขืจืขืื ื ืื ืืืึธืก ืืขื ืขื ืคึฟืึทืจืืื ืื ืืืจื SSH, ืฆื ืืืจืืคึฟืืจื ืึธืคึผืขืจืึทืฆืืขืก ืืื ืืขื "allow_active" ืงืึธื ืืขืงืกื. ืื ืคึผืจืึธืืืขื ืืื ืกืคึผืขืฆืืคึฟืืฉ ืฆื PAM ืกืขืืืื ืืก ืืื openSUSE Leap 15 ืืื SUSE. Linux ืขื ืืขืจืคึผืจืืื 15, ืืื ืขืจืฉืืื ื ื ืึธืจ ืืื ืื ืคืึทืจืฉืคึผืจืืืืื ืืขื.
ืืขืจ pam_env ืืึธืืื ืืื openSUSE ืืื SUSE ืืื ืืืจื ืืืคืึธืื ืึทืงืืืืืืืืจื ืฆื ืืืืขื ืขื ืื ~/.pam_environment ืืขืงืข. ืื ืืขืงืข ืขืจืืืืื ืืขื ืืึทื ืืฆืขืจ ืฆื ืฉืืขืื ืื ืกืืืื ืืืขืจืืึทืืึทืื XDG_SEAT=seat0 ืืื XDG_VTNR=1, ืืืึธืก ืืืขืื ืืืขืจื ืคึผืจืึทืกืขืกื ืืื ืืึทืืืืึทื ืคืื ืืขื ืืึทื ืืฆืขืจ'ืก ืคืืืืฉืขืจ ืืืึทืืืึทื, ืืคืืื ืืืื ืืขืจ ืืึทื ืืฆืขืจ ืืื ืืึทืงืข ืืืื ืืขืืึธืื ืืืจื SSH. ืืขืจ pam_env ืืึธืืื ืืืขืจื ืืืื ืืขืจืืคื ืืืขื ืืขื ืงืึทื ืขืงื ืืืจื SSH. Debian 12 ืืื Ubuntu 24.04 (ืืื Debian 13 ืืื Ubuntu 24.10+ ืืื ืขืก ืืคืืขืฉืืขืื), ืืืขืจ ืฉืืขืื ืกืืืื ืืืขืจืืึทืืืขื ืืื ืื ืืืกืืจืืืืืฉืึทื ื ืงืขื ื ืืฉื ืืืขืจื ืืขื ืืฆื ืฆื ืคืึทืจืืจืขืกืขืจื ืืขื ืึทืงืกืขืก ืืขืืืขื ืฆื "allow_active", ืืืืื pam_env ืืืขืจื ืืขืจืืคื ืืื ืืขืจ ืืขืฆืืขืจ ืฉืืึทืคึผื ื ืึธื ืืึธืื ืืขื pam_systemd ืืึธืืื ืืื ืื ืืืื ืืขืฉืืขืืืข ืกืืืื ืืืขืจืืึทืืืขื ืงืขื ืขื ื ืืฉื ืึทืคืขืงืืืจื ืื ืกืขืกืืข ืคึผืึทืจืึทืืขืืขืจืก.
ืืืึธืก ืฉืืื ืื ืฉืืืึทืืงืืื ืืื libblockdev, ืงืขื ืึทื ืึทืืึทืงืืจืขืจ ืืึธื ืืืจื ืึทื ืืืื ืคึฟืื ืึทื ืึทืจืืืืจืขืจืขืจ ืืขืงืข ืกืืกืืขื ืืื ืืืคึผ ืืึธืืข, ืืื ืฉืืขืื ืึทื ืขืงืกืขืงืืืึทืืืข ืืขืงืข ืืืื SUID ืืืึธืจืฆื ืคึฟืึธื ืึธืืขืจ ืึท ืกืคึผืขืฆืืขืืข ืืขืืืืก (/dev/mem) ืคึฟืึทืจ ื ืืืขืจืืง-ืืขืืืขื ืึทืงืกืขืก ืฆื ืืืกืงืก ืึธืืขืจ ืืึผืจืื ืืื ืืขื ืืืื. ืึผืื ืฆื ืืืึธืงืืจื ืึทืืขืืืข ืึทืืึทืงืขืก, ืืืขืจื FS ืืืืืขืจ ืืึธื ืืืจื ืืืจื ืืขื ืกืืกืืขื ืืื ืื nosuid ืืื nodev ืคึฟืึธื ืขื, ืึธืืขืจ ืื ืฉืืืึทืืงืืื ืืื libblockdev ืืึทืื ืขืก ืืขืืืขื ืฆื ืืึธื ืืืจื ืึทื ืืืื ืึธื ืื nosuid ืืื nodev ืคึฟืึธื ืขื. ืื ืขืกืขื ืฅ ืคึฟืื ืืขืจ ืฉืืืึทืืงืืื ืืื ืึทื udisks ืขืจืืืืื ืึท ืืึทื ืืฆืขืจ ืืืื "allow_active" ืึทืงืกืขืก ืืขืืืขื ืฆื ืขื ืืขืจื ืื ืืจืืืก ืคึฟืื ืืืืขืจืข ืืขืงืข ืกืืกืืขืืขื, ืืื libblockdev ืืึธื ืืืจื ืฆืืืืืืืืืืง ืืขื FS ืึธื ืฆื ืฉืืขืื ืื nosuid ืืื nodev ืคึฟืึธื ืขื ืืขืช โโืืขื ืึธืคึผืขืจืึทืฆืืข.
ืืืื, ืืขืจ ืืืืงืข ืงืืื ืืจืืค ืฆื ืฉืืคื ื ืืืคึผ ืืขืืืืืก ืืืืืจื ืืืืฃ ืื XFS ืคืืื ืกืืกืืขื ืืืื ืืืืก ืื ืืืืื ื suid ืจืื ืคืืื, ืื ืคืื ืืขื ืื ืืคืขืจืืฆืืข ืฆื ืขื ืืขืจื ืื ืืจืืืก ืคืื ืืขื ืืืคึผ ืืขืืืืืก, ืืื ืืื ืืืืจื ืืขื ืืืืขื ื ืืืืก ืขืก ืืืขืจื ืืื ืกืืืืืจื ืืื ืืขื /tmp/blockdev* ืืืจืขืงืืืจื: victim> killall -KILL gvfs-udisks2-volume-monitor victim> udisksctl loop-setup โืคืืื ./xfs.image โno-user-interaction ืืขืืืคืืข ืคืืื ./xfs.image ืืืก /dev/loop0. victim> while true; do /tmp/blockdev*/bash -c 'sleep 10; ls -l /tmp/blockdev*/bash' && break; ืืขืืื 2>/dev/null & victim> gdbus ืจืืฃ โืกืืกืืขื โdest org.freedesktop.UDisks2 โืืืืขืงื-ืืืขื /org/freedesktop/UDisks2/block_devices/loop0 โืืขืืื org.freedesktop.UDisks2.Filesystem.Resize 0 '{}' ืืขืืช: GDBus.Error:org.freedesktop.UDisks2.Error.Failed: ืืขืืช ืืืื ืืืืฉื ืื ืืจืืืก ืคืื ืคืืืืกืืกืืขื ืืืืฃ /dev/loop0: ื ืืฉื ืืขืงืขื ื ืืจืืคื ืขืืขื '/dev/loop0' ื ืืืืขื ืืืืก ืขืก ืืื ืืืืฉื ืื ืืจืืืก: ืฆืื ืืื ืคืืจื ืืืขื -r-sr-xr-x. 1 ืืืึธืจืฆื ืืืึธืจืฆื 1406608 ืืื ื 18 09:42 /tmp/blockdev.RSM429/bash victim> /tmp/blockdev*/bash -p victim# id uid=65534(ืงืืื ืขืจ) gid=65534(ืงืืื ืขืจ) euid=0(ืืืึธืจืฆื) groups=65534(ืงืืื ืขืจ)
ืื ืฉืืืึทืืงืืื ืืื libblockdev ืืื ื ืึธืจ ืืื ืืืฆื ืืขืคึผืึทืืฉื ืืขืืืึธืจื. ืืืจ ืงืขื ื ืงืึธื ืืจืึธืืืจื ืืขื ืกืืึทืืืก ืคืื ืึท ื ืืึทืขืจ ืคึผืึทืงืขื ืืืขืจืกืืข ืึธืืขืจ ืืขื ืคึผืึทืืฉ ืฆืืืจืืืืื ื ืคึผืจืึธืฆืขืก ืคึฟืึทืจ ืืืืขืจืข ืืืกืืจืืืืืฉืึทื ื ืืืืฃ ืื ืคืืืืขื ืืข ืืืขืืขืจ (ืืืื ืึท ืืืึทื ืืื ื ืืฉื ืื ืืืฆื, ืืึธืื ืื ืืืกืืจืืืืืฉืึทื ืก ืืขืืืขืืึธืคึผืขืจืก ื ืึธื ื ืืฉื ืึธื ืืขืืืืื ืืืืกืคืึธืจืฉื ืืขื ืคึผืจืึธืืืขื): Debian, Ubuntu, ืคืขืืึธืจืึท, SUSE/openSUSE, RHEL, ืืืฉืขื ืืึธ, ืืื ืึทืจืืฉ (1, 2). ืึทืืก ืึทื ืึทืจืืืืึทื ื ืฆื ืืืึธืงืืจื ืื ืืืึทืื ืขืจืึทืืืืืื, ืงืขื ื ืืืจ ืืึธืืืคืืฆืืจื ืื ืึทืงืกืขืก ืืขืจืฉื ืคึฟืึทืจ ืื "org.freedesktop.udisks2.modify-device" ืึธืคึผืขืจืึทืฆืืข ืืื ืคึผืึธืืงืื ืืืจื ืขื ืืขืจื ืืขื "allow_active" ืคึผืึทืจืึทืืขืืขืจ ืคึฟืื "yes" ืฆื "auth_admin" ืืื ืืขืจ /usr/share/polkit-1/actions/org.freedesktop.UDisks2.policy ืืขืงืข.
ืืขืจืฆื, ื ืฉืืืืืงืืื (CVE-2025-6020) ืืื ืืขื ืืื ืืงืก-ืคึผืึทื ืคึผืขืงื, ืืืึธืก ืืื ืืขืืืึธืจื ืึทื ืืคึผืืขืงื ืขืืืขืืข ืฉืขื ืฆืืจืืง, ืขืจืืืืื ืึท ืืึธืงืึทืื ืืึทื ืืฆืขืจ ืฆื ืืึทืงืืืขื ืจืื ืคึผืจืืืืืืขืืืขืก. ืืขืจ pam_namespace ืืึธืืื ืืึธื ื ืืฉื ืจืืืืืง ืืืึทืืืืืจื ืืึทื ืืฆืขืจ-ืงืึธื ืืจืึธืืืจืืข ืืขืงืข ืคึผืึทืืก, ืืืึธืก ืืึธื ืขืจืืืืื ืคึผืจืืืืืืขืืืจืืข ืืขืงืขืก ืฆื ืืืขืจื ืืืืขืจืืขืฉืจืืื ืืื ืกืืกืืขื ืืืจื ืกืืืืึธืืืฉืข ืืื ืง ืืึทื ืืคึผืืืึทืฆืืข ืืื ืจืึทืกืข ืืืืื ืืื ืืขื. ืื ืฉืืืืืงืืื ืืื ืืขืืืึธืจื ืคืึทืจืจืืื ืืื ืืื ืืงืก-ืคึผืึทื 1.7.1. ืืืจ ืงืขื ื ืงืึธื ืืจืึธืืืจื ืืขื ืกืืึทืืืก ืคืื ืืขืจ ื ืืืขืจ ืคึผืขืงื ืืืขืจืกืืข ืึธืืขืจ ืืขื ืคึผืึทืืฉ ืืืึธืก ืืืขืจื ืฆืืืขืืจืืื ืคึฟืึทืจ ืืืกืืจืืืืืฉืึทื ื ืืืืฃ ืื ืคืืืืขื ืืข ืืืขืืขืจ: Debian, Ubuntu, ืคืขืืึธืจืึท, SUSE/openSUSE, RHEL, ืืืฉืขื ืื ืืื ืึทืจืืฉ (1, 2).
ืืงืืจ: opennet.ru
