[DSA 6414-1] udisks2 security update

Alberto Garcia <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6414-1                   [email protected]
https://www.debian.org/security/                           Alberto Garcia
August 06, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : udisks2
CVE ID         : CVE-2026-7867

The following vulnerability has been discovered in the UDisks storage
daemon:

CVE-2026-7867

    Azizcan Dastan and Ozlem Ozan discovered a local privilege
    escalation vulnerability in udisks2 involving the Filesystem.Mount
    D-Bus method. Using the 'as-user' option, an unprivileged local
    user can in some cases influence the mount execution path so that
    a filesystem mount is performed in a privileged/root context
    without the expected PolicyKit authorization behavior.

For the stable distribution (trixie), this problem has been fixed in
version 2.10.1-12.1+deb13u2.

We recommend that you upgrade your udisks2 packages.

For the detailed security status of udisks2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/udisks2

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmp0tx8ACgkQAAyEYu0C
2AKm+g//W40oNaNJx0qFBtQwNeqlh0wrV0ynWngVeYqxv+E0Q3CZaK3wwkiAvTmP
bY5bC/PQwBcZPLTrO476eCqAlOL37hS3kIqSh+Ypn4AIC/ZXCRQwAaRebZdwMl8p
uMlHKiFlCXqD4ebqquYVD7Dc55lwYIuMmu+Dv7lEKouBi5c5PYfRGnpzr7K7w662
roe/j9QPC2nlsR485EIzmUUIqQFbYUotn+92DUw2d/pdpQR7miU5R0j7rvq96ltB
DoLFlC6o91lkI/2Gxn16a2thgWLA1kpqM4/OpNb3b1hhbVRp1oHhOlptEwQxSTrU
yVTnGn67XnwOZJinnMQytDDnnURMztG3KWNHCxYdQDiLzwGHlTpEb00KfLEBeCX1
1cnMuYvF2X1UZ6U0GMtiPua/YK0z9L3S/Jtzzz8+rCu2xo81PxuyaXgvq4A5ww2C
iZZaI4f4lIYgFL/3zD5xAT+hJL7kluCW4YYMr2+TiN8vRhIibTiXOEZu7qLbHT4p
y2nr3KYeurFcOh7j8qPaMg7qzQtaKjxvUjMaKuj6tr23FHgk5AgLhk1ndG4reK6d
tG3L1K207DgvFU/20u67U+WpXahGdoEex6ZP7OnSI2y/l/i2+NoHOyfA/uvt8u07
KxD0ATOHJKQ98ivkIZr9fE1irW7ODsQvJcpRfDssIrx3+ss3ncw=
=SmoR
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.