Home / mailingsPDF  

[USN-8701-1] UDisks vulnerability

Posted on 31 August 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8701-1
August 31, 2026

udisks2 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS

Summary:

UDisks could be made to run programs as an administrator.

Software Description:
- udisks2: service to access and manipulate storage devices

Details:

It was discovered that UDisks did not correctly validate the caller
identity when handling the as-user option in the
org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. A local attacker
with an active console session could possibly use this issue to mount
filesystems on behalf of arbitrary users, including privileged accounts,
leading to local privilege escalation.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libudisks2-0 2.10.91-1ubuntu2.1
udisks2 2.10.91-1ubuntu2.1

Ubuntu 24.04 LTS
libudisks2-0 2.10.1-6ubuntu1.5
udisks2 2.10.1-6ubuntu1.5

After a standard system update you need to reboot your computer to make all
the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8701-1
CVE-2026-7867

Package Information:
https://launchpad.net/ubuntu/+source/udisks2/2.10.91-1ubuntu2.1
https://launchpad.net/ubuntu/+source/udisks2/2.10.1-6ubuntu1.5

--===============7730911178367840057==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP