CVE-2025-7519: Red Hat Enterprise Linux

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is needed as it's required to place the malicious policy file properly.

Affected products

  • Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only; version 9.0 only; version 10.0 only
  • Red Hat Openshift Container Platform: version 4.0 only

Published 2025-07-14. Last modified 2026-09-01.