CVE-2025-7519: Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write
A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is needed as it's required to place the malicious policy file properly.
Other sources
Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write
— Microsoft
When polkit is processing a XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This can lead polkit to crash or other unexpected behavior and arbitrary code execution is not discarded. To explore this flaw, a high privilege account is needed as it's required to properly place the malicious policy file.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7519?
CVE-2025-7519 is considered to have a high severity due to its potential for arbitrary code execution and system crashes.
How do I fix CVE-2025-7519?
To fix CVE-2025-7519, ensure you update to the latest patched version of polkit as soon as it becomes available.
Which versions of polkit are affected by CVE-2025-7519?
CVE-2025-7519 affects all versions of polkit that process XML policies with excessive nesting.
What are the potential impacts of CVE-2025-7519?
The potential impacts of CVE-2025-7519 include application crashes and unpredictable behavior in systems utilizing polkit.
Can CVE-2025-7519 be exploited remotely?
Exploitation of CVE-2025-7519 may require local access or high privileges, depending on the implementation.