关键漏洞信息 漏洞概述 类型/严重性: 安全公告 - 重要 主题: libblockdev的安全更新,适用于Red Hat Enterprise Linux 10。 描述: libblockdev包提供了一个C库,用于块设备的低级操作。该库作为围绕plug-ins的薄包装器,用于特定功能,如LVM、Btrfs、LUKS或MD RAID。 安全修复 CVE-2025-6019: libblockdev中的本地权限提升(LPE)漏洞,允许通过udisks将allow_active设置为root。 受影响的产品 Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 7.6+ Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 解决方案 详情请参阅: https://access.redhat.com/articles/11258 CVEs CVE-2025-6019 参考资料 https://access.redhat.com/security/updates/classification/#important