UDisks Vulnerability Allows Local Privilege Escalation in Ubuntu

UDisks Vulnerability Allows Local Privilege Escalation in Ubuntu

First seen 31 Aug 2026, 16:30 UTC UbuntuLinuxsecurity 57.1

Article Content

Browse articles
ThreatCluster

A vulnerability in UDisks was discovered that fails to validate caller identity when using the as-user option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This flaw allows a local attacker with an active console session to mount filesystems on behalf of arbitrary users, including privileged accounts, leading to local privilege escalation. The affected versions include UDisks 2.10.91-1ubuntu2.1 for Ubuntu 26.04 and 2.10.1-6ubuntu1.5 for Ubuntu 24.04. Users are advised to update their systems to mitigate this risk. A reboot is required after applying the updates. The vulnerability is significant as it could allow unauthorized access to sensitive data and system controls. No active exploitation has been reported as of now, but the potential for misuse exists. The issue has been documented in Ubuntu Security Notice USN-8701-1.

Key Points: • UDisks vulnerability allows local privilege escalation on Ubuntu systems. • Affected versions include UDisks 2.10.91-1ubuntu2.1 and 2.10.1-6ubuntu1.5. • Users must update and reboot their systems to mitigate the risk.

Timeline

2026-08-31
UDisks vulnerability disclosed
A flaw in UDisks allows local attackers to mount filesystems on behalf of other users, leading to privilege escalation.
Ubuntu
2026-08-31
Patch released for UDisks
Updates for UDisks were released to address the vulnerability, requiring users to reboot their systems after installation.
Linuxsecurity