USN-8701-1

Source
https://ubuntu.com/security/notices/USN-8701-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8701-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8701-1
Upstream
Related
Published
2026-08-31T12:24:24Z
Modified
2026-08-31T22:26:26.938977178Z
Summary
udisks2 vulnerability
Details

It was discovered that UDisks did not correctly validate the caller identity when handling the as-user option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. A local attacker with an active console session could possibly use this issue to mount filesystems on behalf of arbitrary users, including privileged accounts, leading to local privilege escalation.

References

Affected packages

Ubuntu:24.04:LTS / udisks2

Package

Name
udisks2
Purl
pkg:deb/ubuntu/udisks2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.1-6ubuntu1.5

Affected versions

2.*
2.10.1-1ubuntu1
2.10.1-1ubuntu2
2.10.1-6
2.10.1-6build1
2.10.1-6ubuntu1
2.10.1-6ubuntu1.2
2.10.1-6ubuntu1.3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2.10.1-6ubuntu1.5",
            "binary_name": "gir1.2-udisks-2.0"
        },
        {
            "binary_version": "2.10.1-6ubuntu1.5",
            "binary_name": "libudisks2-0"
        },
        {
            "binary_version": "2.10.1-6ubuntu1.5",
            "binary_name": "udisks2"
        },
        {
            "binary_version": "2.10.1-6ubuntu1.5",
            "binary_name": "udisks2-btrfs"
        },
        {
            "binary_version": "2.10.1-6ubuntu1.5",
            "binary_name": "udisks2-lvm2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8701-1.json"
cves_map
{
    "ecosystem": "Ubuntu:24.04:LTS",
    "cves": [
        {
            "id": "CVE-2026-7867",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}

Ubuntu:26.04:LTS / udisks2

Package

Name
udisks2
Purl
pkg:deb/ubuntu/udisks2?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.91-1ubuntu2.1

Affected versions

2.*
2.10.1-12.1ubuntu2
2.10.91-1ubuntu1
2.10.91-1ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2.10.91-1ubuntu2.1",
            "binary_name": "gir1.2-udisks-2.0"
        },
        {
            "binary_version": "2.10.91-1ubuntu2.1",
            "binary_name": "libudisks2-0"
        },
        {
            "binary_version": "2.10.91-1ubuntu2.1",
            "binary_name": "udisks2"
        },
        {
            "binary_version": "2.10.91-1ubuntu2.1",
            "binary_name": "udisks2-btrfs"
        },
        {
            "binary_version": "2.10.91-1ubuntu2.1",
            "binary_name": "udisks2-lvm2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8701-1.json"
cves_map
{
    "ecosystem": "Ubuntu:26.04:LTS",
    "cves": [
        {
            "id": "CVE-2026-7867",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}