Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61898

Опубликовано: 20 авг. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.

A flaw was found in accountsservice. A local attacker can exploit this by injecting arbitrary shell commands into the user-controlled LANGUAGE entry in the ~/.pam_environment file. The Ubuntu-specific language helper scripts process this input unescaped, leading to arbitrary code execution with root privileges via the SetLanguage D-Bus method.

Отчет

This Important vulnerability in accountsservice is specific to Ubuntu's language helper scripts. Red Hat products do not utilize these particular scripts, therefore, this flaw does not affect Red Hat Enterprise Linux or its supported derivatives.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10accountsserviceNot affected
Red Hat Enterprise Linux 7accountsserviceNot affected
Red Hat Enterprise Linux 8accountsserviceNot affected
Red Hat Enterprise Linux 9accountsserviceNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2520354accountsservice: accountsservice: Arbitrary code execution via shell injection

EPSS

Процентиль: 3%
0.0013
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
15 дней назад

The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.

CVSS3: 7.8
nvd
15 дней назад

The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.

CVSS3: 7.8
debian
15 дней назад

The Ubuntu-specific language helper scripts (save-to-pam-env, update-l ...

CVSS3: 7.8
github
15 дней назад

The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.

EPSS

Процентиль: 3%
0.0013
Низкий

7.8 High

CVSS3