-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6414-1                   [email protected]
https://www.debian.org/security/                           Alberto Garcia
August 06, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : udisks2
CVE ID         : CVE-2026-7867

The following vulnerability has been discovered in the UDisks storage
daemon:

CVE-2026-7867

    Azizcan Dastan and Ozlem Ozan discovered a local privilege
    escalation vulnerability in udisks2 involving the Filesystem.Mount
    D-Bus method. Using the 'as-user' option, an unprivileged local
    user can in some cases influence the mount execution path so that
    a filesystem mount is performed in a privileged/root context
    without the expected PolicyKit authorization behavior.

For the stable distribution (trixie), this problem has been fixed in
version 2.10.1-12.1+deb13u2.

We recommend that you upgrade your udisks2 packages.

For the detailed security status of udisks2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/udisks2

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmp0tx8ACgkQAAyEYu0C
2AKm+g//W40oNaNJx0qFBtQwNeqlh0wrV0ynWngVeYqxv+E0Q3CZaK3wwkiAvTmP
bY5bC/PQwBcZPLTrO476eCqAlOL37hS3kIqSh+Ypn4AIC/ZXCRQwAaRebZdwMl8p
uMlHKiFlCXqD4ebqquYVD7Dc55lwYIuMmu+Dv7lEKouBi5c5PYfRGnpzr7K7w662
roe/j9QPC2nlsR485EIzmUUIqQFbYUotn+92DUw2d/pdpQR7miU5R0j7rvq96ltB
DoLFlC6o91lkI/2Gxn16a2thgWLA1kpqM4/OpNb3b1hhbVRp1oHhOlptEwQxSTrU
yVTnGn67XnwOZJinnMQytDDnnURMztG3KWNHCxYdQDiLzwGHlTpEb00KfLEBeCX1
1cnMuYvF2X1UZ6U0GMtiPua/YK0z9L3S/Jtzzz8+rCu2xo81PxuyaXgvq4A5ww2C
iZZaI4f4lIYgFL/3zD5xAT+hJL7kluCW4YYMr2+TiN8vRhIibTiXOEZu7qLbHT4p
y2nr3KYeurFcOh7j8qPaMg7qzQtaKjxvUjMaKuj6tr23FHgk5AgLhk1ndG4reK6d
tG3L1K207DgvFU/20u67U+WpXahGdoEex6ZP7OnSI2y/l/i2+NoHOyfA/uvt8u07
KxD0ATOHJKQ98ivkIZr9fE1irW7ODsQvJcpRfDssIrx3+ss3ncw=
=SmoR
-----END PGP SIGNATURE-----

Reply via email to