-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6414-1 [email protected]
https://www.debian.org/security/ Alberto Garcia
August 06, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : udisks2
CVE ID : CVE-2026-7867
The following vulnerability has been discovered in the UDisks storage
daemon:
CVE-2026-7867
Azizcan Dastan and Ozlem Ozan discovered a local privilege
escalation vulnerability in udisks2 involving the Filesystem.Mount
D-Bus method. Using the 'as-user' option, an unprivileged local
user can in some cases influence the mount execution path so that
a filesystem mount is performed in a privileged/root context
without the expected PolicyKit authorization behavior.
For the stable distribution (trixie), this problem has been fixed in
version 2.10.1-12.1+deb13u2.
We recommend that you upgrade your udisks2 packages.
For the detailed security status of udisks2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/udisks2
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmp0tx8ACgkQAAyEYu0C
2AKm+g//W40oNaNJx0qFBtQwNeqlh0wrV0ynWngVeYqxv+E0Q3CZaK3wwkiAvTmP
bY5bC/PQwBcZPLTrO476eCqAlOL37hS3kIqSh+Ypn4AIC/ZXCRQwAaRebZdwMl8p
uMlHKiFlCXqD4ebqquYVD7Dc55lwYIuMmu+Dv7lEKouBi5c5PYfRGnpzr7K7w662
roe/j9QPC2nlsR485EIzmUUIqQFbYUotn+92DUw2d/pdpQR7miU5R0j7rvq96ltB
DoLFlC6o91lkI/2Gxn16a2thgWLA1kpqM4/OpNb3b1hhbVRp1oHhOlptEwQxSTrU
yVTnGn67XnwOZJinnMQytDDnnURMztG3KWNHCxYdQDiLzwGHlTpEb00KfLEBeCX1
1cnMuYvF2X1UZ6U0GMtiPua/YK0z9L3S/Jtzzz8+rCu2xo81PxuyaXgvq4A5ww2C
iZZaI4f4lIYgFL/3zD5xAT+hJL7kluCW4YYMr2+TiN8vRhIibTiXOEZu7qLbHT4p
y2nr3KYeurFcOh7j8qPaMg7qzQtaKjxvUjMaKuj6tr23FHgk5AgLhk1ndG4reK6d
tG3L1K207DgvFU/20u67U+WpXahGdoEex6ZP7OnSI2y/l/i2+NoHOyfA/uvt8u07
KxD0ATOHJKQ98ivkIZr9fE1irW7ODsQvJcpRfDssIrx3+ss3ncw=
=SmoR
-----END PGP SIGNATURE-----