7.8

CVE-2026-61897

accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCanonical
Produkt accountsservice
Default Statusunaffected
Version 22.07.5-2ubuntu1
Version < 22.07.5-2ubuntu1.6
Status affected
Version 23.13.9-2ubuntu6
Version < 23.13.9-2ubuntu6.1
Status affected
Version 23.13.9-8ubuntu5
Version < 23.13.9-8ubuntu5.2
Status affected
Version 23.13.9-8ubuntu6
Version < 23.13.9-8ubuntu7
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Canonical 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-273 Improper Check for Dropped Privileges

The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.

https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2157985
https://ubuntu.com/security/CVE-2026-61897