Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16743

Опубликовано: 23 июл. 2026
Источник: redhat
CVSS3: 5.5

Описание

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.

Отчет

Red Hat Enterprise Linux is not affected. The accountsservice versions shipped in RHEL do not include the systemd-homed SetIconFile code path introduced in later upstream releases.

Меры по смягчению последствий

Avoid using systemd-homed-managed accounts on systems running a vulnerable accountsservice build.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10accountsserviceFix deferred
Red Hat Enterprise Linux 7accountsserviceOut of support scope
Red Hat Enterprise Linux 8accountsserviceFix deferred
Red Hat Enterprise Linux 9accountsserviceFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2506381accountsservice: accountsservice: arbitrary file read via SetIconFile for systemd-homed users

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
24 дня назад

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.

CVSS3: 5.5
nvd
24 дня назад

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.

CVSS3: 5.5
debian
24 дня назад

A flaw was found in accountsservice. The systemd-homed code path for S ...

CVSS3: 5.5
github
24 дня назад

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.

5.5 Medium

CVSS3