Linuxsecurity
UDisks Vulnerability Allows Local Privilege Escalation in Ubuntu
Article Content
A vulnerability in UDisks was discovered that fails to validate caller identity when using the as-user option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This flaw allows a local attacker with an active console session to mount filesystems on behalf of arbitrary users, including privileged accounts, leading to local privilege escalation. The affected versions include UDisks 2.10.91-1ubuntu2.1 for Ubuntu 26.04 and 2.10.1-6ubuntu1.5 for Ubuntu 24.04. Users are advised to update their systems to mitigate this risk. A reboot is required after applying the updates. The vulnerability is significant as it could allow unauthorized access to sensitive data and system controls. No active exploitation has been reported as of now, but the potential for misuse exists. The issue has been documented in Ubuntu Security Notice USN-8701-1.
Key Points: • UDisks vulnerability allows local privilege escalation on Ubuntu systems. • Affected versions include UDisks 2.10.91-1ubuntu2.1 and 2.10.1-6ubuntu1.5. • Users must update and reboot their systems to mitigate the risk.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.