Four new Linux vulnerabilities confirmed, two have gone undetected for 12 years

If I were to mention security vulnerabilities, what vendors or products immediately come to mind? Now, I’m not Paul McKenna, but I can see Microsoft Windows and Google Chrome with my mind’s eye. But here’s the thing: security vulnerabilities are a reality for every vendor and every product, including those that are generally considered to be more secure than others.

Take Linux, which is often touted as a very secure operating system. Security researchers have uncovered four critical vulnerabilities affecting Linux, and two of those have remained undetected for the past 12 years.

Let’s start with the 12-year-olds. The vulnerabilities, CVE-2025-32462 and CVE-2025-32463, were discovered by Rich Mirch, Principal Consultant at the Stratascale Cyber Research Unit. These could enable a local user to escalate privileges to root, without needing an exploit to do so.

This took advantage of one of the most widely used system tools in the Linux world, Sudo, and has gone unnoticed for more than a decade. Wowsers. How widely used? Well Sudo is installed on 99% of Linux servers, powering 90% of public cloud services. Given that there are around 100 million active Linux users as well, this is a big deal.

“It’s important to understand that long-undetected vulnerabilities like this highlight critical gaps in visibility across digital infrastructures,” Mirch said. “These exposures aren’t just technical failures, they are operational risks that can undermine trust, identity and compliance.”

He’s not wrong. If these vulnerabilities have gone undetected for so long, how many others have as well? The vulnerabilities serve “as a call to reassess how effectively your security investments are surfacing latent risks,” Mirch said, not being wrong again.

Two more Linux vulnerabilities

As for the remaining two Linux vulnerabilities, a proof-of-concept and details have been published by the Qualys Threat Research Unit, revealing both can also be exploited for local privilege escalation.

CVE-2025-6018 resides in the PAM configuration of openSUSE Leap 15 and SUSE Linux Enterprise 15. Meanwhile CVE-2025-6019 affects libblockdev and is exploitable via the udisks daemon, included by default on most Linux distributions.

“Although CVE-2025-6019 on its own requires existing allow_active context,” said a Qualys Threat Research Unit spokesperson, “chaining it with CVE-2025-6018 enables a purely unprivileged attacker to achieve full root access, making these flaws extremely impactful.”

By chaining the two vulnerabilities, an attacker can get SUSE 15/Leap 15 SSH user leap from normal to root with the default PAM and udisks installed, because one vulnerability grants an allow active command and the next turns into a full root that enables, Qualys said, “agent tampering, persistence, and lateral movement”.

In other words, a single unpatched Linux server can endanger your whole fleet. 

So, you know what to do. Get patching now and stop thinking that Linux is somehow inherently secure.

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.