CVE-2025-7519: Red Hat Enterprise Linux
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is needed as it's required to place the malicious policy file properly.
Affected products
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only; version 9.0 only; version 10.0 only
- Red Hat Openshift Container Platform: version 4.0 only
Published 2025-07-14. Last modified 2026-09-01.