Junglewise Threat Intelligence

CVE-2025-8067: storaged-project udisks privilege escalation in D-BUS loop device handler

CVE-2025-8067 · Severity: high · CVSS 8.5 · Published 2025-08-28

Technologies: Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10. Vendors: Red Hat.

Executive brief

A security vulnerability has been identified in the Udisks daemon, a background service used by Linux systems to manage storage devices and disks. An unprivileged user can exploit this flaw to crash the system service or gain unauthorized access to sensitive files owned by administrative users. This could lead to a complete system disruption or a full takeover of the affected machine by a local attacker.

Technical details

A vulnerability exists in the Udisks daemon's loop device handler, which processes requests via the D-BUS system interface. The handler accepts a file descriptor list and an index parameter to specify the backing file for a loop device. While the function validates the upper bound of the index, it fails to validate the lower bound, allowing a negative index value to be processed. This out-of-bounds read/access can be leveraged by a local, unprivileged attacker to crash the daemon (Denial of Service) or potentially gain access to privileged files, leading to local privilege escalation. Patches have been released by Red Hat and the upstream storaged-project.

Affected products

  • storaged-project udisks2 < 2.10.2, 2.10.3 to < 2.10.91
  • Red Hat Red Hat Enterprise Linux 8 < 2.9.0-16.el8_10.1
  • Red Hat Red Hat Enterprise Linux 9 < 2.10.1-11.el9_4.1
  • Red Hat Red Hat Enterprise Linux 10 < 2.10.90-5.el10_0.1

Timeline

  • 2025-08-28: disclosed
  • 2025-08-28: advisory: NVD publication date
  • 2025-09-02: patched: Red Hat security updates released

References

Related threats