CVE-2026-7867

high
Published 2026-08-06 · Modified 2026-08-07
CVSS v3
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
not yet in upstream
VIR risk
7.8

Description

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-7867 NameCVE-2026-7867 DescriptionA flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts.…

CVE-2026-7867

NameCVE-2026-7867
DescriptionA flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6414-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
udisks2 (PTS)bullseye2.9.2-2+deb11u1fixed
bullseye (security)2.9.2-2+deb11u3fixed
bookworm, bookworm (security)2.9.4-4+deb12u2fixed
trixie2.10.1-12.1+deb13u1vulnerable
trixie (security)2.10.1-12.1+deb13u2fixed
forky2.11.1-2vulnerable
sid2.11.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
udisks2sourcebullseye(not affected)
udisks2sourcebookworm(not affected)
udisks2sourcetrixie2.10.1-12.1+deb13u2DSA-6414-1
udisks2source(unstable)2.11.2-1

Notes

[bookworm] - udisks2 <not-affected> (udisks2 versions < 2.10.x are not affected)
[bullseye] - udisks2 <not-affected> (udisks2 versions < 2.10.x are not affected)
https://github.com/azqzazq1/CVE-2026-7867-disk2root
https://github.com/storaged-project/udisks/security/advisories/GHSA-j42g-v9jw-6ph3
https://github.com/storaged-project/udisks/commit/397eea88d58f77f6e02d537c4c961201b9245943
https://github.com/storaged-project/udisks/commit/0050f51d40e468f6a3197ccdc77b5bd59c923a37
https://github.com/storaged-project/udisks/commit/98e5a76c155640d155280cdb642791f00def736a
https://github.com/storaged-project/udisks/commit/681d58a76f6aaa5045eb43e665c65f497d35b810
https://github.com/storaged-project/udisks/commit/36231768dde088c8b4d4796ff2d311d089d84052
Backport for 2.10.y: https://github.com/storaged-project/udisks/pull/1530

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[bookworm] - udisks2 <not-affected> (udisks2 versions < 2.10.x are not affected)[bullseye] - udisks2 <not-affected> (udisks2 versions < 2.10.x are not affected)https://github.com/azqzazq1/CVE-2026-7867-disk2roothttps://github.com/storaged-project/udisks/security/advisories/GHSA-j42g-v9jw-6ph3https://github.com/storaged-project/udisks/commit/397eea88d58f77f6e02d537c4c961201b9245943https://github.com/storaged-project/udisks/commit/0050f51d40e468f6a3197ccdc77b5bd59c923a37https://github.com/storaged-project/udisks/commit/98e5a76c155640d155280cdb642791f00def736ahttps://github.com/storaged-project/udisks/commit/681d58a76f6aaa5045eb43e665c65f497d35b810https://github.com/storaged-project/udisks/commit/36231768dde088c8b4d4796ff2d311d089d84052Backport for 2.10.y: https://github.com/storaged-project/udisks/pull/1530

OS impact

debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Fixed 2.10.1-12.1+deb13u2
sid Fixed 2.11.2-1
forky Affected
bullseye Fixed 0
bookworm Fixed 0

References

CWEs

CWE-863

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.