CVE-2025-53391: Debian Zulucrypt
Critical severity, CVSS 9.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_active settings that allow a local user to escalate their privileges to root.
Affected products
- Debian Zulucrypt
Published 2025-06-28. Last modified 2026-06-17.