Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61897

Опубликовано: 20 авг. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.

A flaw was found in AccountsService. An Ubuntu-specific patch for AccountsService did not fully drop root privileges when launching language helper scripts. This oversight allows a local user to exploit the incomplete privilege drop, potentially enabling them to reset their effective user ID to root. This could lead to local privilege escalation, granting unauthorized administrative access to the system.

Отчет

This Important vulnerability in AccountsService stems from an Ubuntu-specific patch that incompletely drops privileges when launching language helper scripts. Red Hat products do not include this specific patch, therefore they are not directly affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10accountsserviceNot affected
Red Hat Enterprise Linux 7accountsserviceNot affected
Red Hat Enterprise Linux 8accountsserviceNot affected
Red Hat Enterprise Linux 9accountsserviceNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-273
https://bugzilla.redhat.com/show_bug.cgi?id=2520352accountsservice: AccountsService: Local privilege escalation via incomplete privilege drop in language helper scripts

EPSS

Процентиль: 1%
0.00097
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 месяца назад

incomplete privilege dropping when calling SetLanguage

CVSS3: 7.8
nvd
15 дней назад

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.

CVSS3: 7.8
debian
15 дней назад

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 on ...

CVSS3: 7.8
github
15 дней назад

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.

EPSS

Процентиль: 1%
0.00097
Низкий

7.8 High

CVSS3