{"id":"CVE-2025-7519","summary":"Polkit: xml policy file with a large number of nested elements may lead to out-of-bounds write","details":"A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is needed as it's required to place the malicious policy file properly.","modified":"2026-09-03T08:05:35.396782Z","published":"2025-07-14T13:35:21.280Z","related":["SUSE-SU-2025:02525-1","SUSE-SU-2025:02527-1","SUSE-SU-2025:02528-1","SUSE-SU-2025:20559-1","SUSE-SU-2025:20662-1","openSUSE-SU-2026:10453-1"],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7519.json"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://www.freedesktop.org/software/polkit/releases/"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-7519"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/7xxx/CVE-2025-7519.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-7519"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2379675"},{"type":"FIX","url":"https://github.com/polkit-org/polkit/commit/107d3801361b9f9084f78710178e683391f1d245"},{"type":"FIX","url":"https://github.com/polkit-org/polkit/pull/570"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/polkit-org/polkit","events":[{"introduced":"0"},{"fixed":"107d3801361b9f9084f78710178e683391f1d245"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"126"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["126","125","124","123","122","121","0.120","0.119","0.118","0.117","0.116","0.115","0.114","0.113","0.112","0.111","0.110","0.109","0.108","0.107","0.106","0.105","0.104","0.103","0.102","0.101","0.100","0.99","0.98","0.97","0.96","0.95","0.94","0.93","0.92","0.91","POLICY_KIT_0_9","POLICY_KIT_0_8","POLICY_KIT_0_7","POLICY_KIT_0_6","POLICY_KIT_0_5","POLICY_KIT_0_4","POLICY_KIT_0_3","start"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-7519.json","vanir_signatures_modified":"2026-09-03T08:05:35Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/polkit-org/polkit/commit/107d3801361b9f9084f78710178e683391f1d245","target":{"file":"src/polkitbackend/polkitbackendactionpool.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["194843406561665307492518022948441502460","256368177087476590824027693163048704477","289543494710369596500892213933305008941"]},"id":"CVE-2025-7519-13428640","signature_type":"Line"},{"digest":{"function_hash":"170222943027964640532293278136544979486","length":3300},"id":"CVE-2025-7519-65be4b0f","signature_type":"Function","signature_version":"v1","source":"https://github.com/polkit-org/polkit/commit/107d3801361b9f9084f78710178e683391f1d245","target":{"file":"src/polkitbackend/polkitbackendactionpool.c","function":"_start"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}