Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21704-1

Опубликовано: 30 авг. 2026
Источник: suse-cvrf

Описание

Security update for udisks2

This update for udisks2 fixes the following issue:

  • CVE-2026-7867: insufficient authorization checks on the as-user option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method can lead to local privilege escalation (bsc#1274430).

Список пакетов

openSUSE Leap 16.0
libudisks2-0-2.10.1-160000.4.1
libudisks2-0-devel-2.10.1-160000.4.1
libudisks2-0_btrfs-2.10.1-160000.4.1
libudisks2-0_lsm-2.10.1-160000.4.1
libudisks2-0_lvm2-2.10.1-160000.4.1
typelib-1_0-UDisks-2_0-2.10.1-160000.4.1
udisks2-2.10.1-160000.4.1
udisks2-bash-completion-2.10.1-160000.4.1
udisks2-docs-2.10.1-160000.4.1
udisks2-lang-2.10.1-160000.4.1
udisks2-zsh-completion-2.10.1-160000.4.1

Описание

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.


Затронутые продукты
openSUSE Leap 16.0:libudisks2-0-2.10.1-160000.4.1
openSUSE Leap 16.0:libudisks2-0-devel-2.10.1-160000.4.1
openSUSE Leap 16.0:libudisks2-0_btrfs-2.10.1-160000.4.1
openSUSE Leap 16.0:libudisks2-0_lsm-2.10.1-160000.4.1

Ссылки