[DSA 6414-1] udisks2 security update
Alberto Garcia <[email protected]>
| Newsgroups | gmane.linux.debian.user.security.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6414-1 [email protected] https://www.debian.org/security/ Alberto Garcia August 06, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : udisks2 CVE ID : CVE-2026-7867 The following vulnerability has been discovered in the UDisks storage daemon: CVE-2026-7867 Azizcan Dastan and Ozlem Ozan discovered a local privilege escalation vulnerability in udisks2 involving the Filesystem.Mount D-Bus method. Using the 'as-user' option, an unprivileged local user can in some cases influence the mount execution path so that a filesystem mount is performed in a privileged/root context without the expected PolicyKit authorization behavior. For the stable distribution (trixie), this problem has been fixed in version 2.10.1-12.1+deb13u2. We recommend that you upgrade your udisks2 packages. For the detailed security status of udisks2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/udisks2 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmp0tx8ACgkQAAyEYu0C 2AKm+g//W40oNaNJx0qFBtQwNeqlh0wrV0ynWngVeYqxv+E0Q3CZaK3wwkiAvTmP bY5bC/PQwBcZPLTrO476eCqAlOL37hS3kIqSh+Ypn4AIC/ZXCRQwAaRebZdwMl8p uMlHKiFlCXqD4ebqquYVD7Dc55lwYIuMmu+Dv7lEKouBi5c5PYfRGnpzr7K7w662 roe/j9QPC2nlsR485EIzmUUIqQFbYUotn+92DUw2d/pdpQR7miU5R0j7rvq96ltB DoLFlC6o91lkI/2Gxn16a2thgWLA1kpqM4/OpNb3b1hhbVRp1oHhOlptEwQxSTrU yVTnGn67XnwOZJinnMQytDDnnURMztG3KWNHCxYdQDiLzwGHlTpEb00KfLEBeCX1 1cnMuYvF2X1UZ6U0GMtiPua/YK0z9L3S/Jtzzz8+rCu2xo81PxuyaXgvq4A5ww2C iZZaI4f4lIYgFL/3zD5xAT+hJL7kluCW4YYMr2+TiN8vRhIibTiXOEZu7qLbHT4p y2nr3KYeurFcOh7j8qPaMg7qzQtaKjxvUjMaKuj6tr23FHgk5AgLhk1ndG4reK6d tG3L1K207DgvFU/20u67U+WpXahGdoEex6ZP7OnSI2y/l/i2+NoHOyfA/uvt8u07 KxD0ATOHJKQ98ivkIZr9fE1irW7ODsQvJcpRfDssIrx3+ss3ncw= =SmoR -----END PGP SIGNATURE-----