7.8
CVE-2026-61897
- EPSS -
- Veröffentlicht 20.08.2026 14:32:53
- Zuletzt bearbeitet 20.08.2026 15:17:38
- CVE-Watchlists
- Unerledigt
accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCanonical
≫
Produkt
accountsservice
Default Statusunaffected
Version
22.07.5-2ubuntu1
Version <
22.07.5-2ubuntu1.6
Status
affected
Version
23.13.9-2ubuntu6
Version <
23.13.9-2ubuntu6.1
Status
affected
Version
23.13.9-8ubuntu5
Version <
23.13.9-8ubuntu5.2
Status
affected
Version
23.13.9-8ubuntu6
Version <
23.13.9-8ubuntu7
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Canonical | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-273 Improper Check for Dropped Privileges
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2157985
https://ubuntu.com/security/CVE-2026-61897