Bug 2466747 (CVE-2026-7867)

Summary: CVE-2026-7867 udisks2: udisks2: Local Privilege Escalation via as-user option spoofing
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: rhel-process-autobot, security-response-team, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2512108    
Bug Blocks:    

Description OSIDB Bzimport 2026-05-05 13:52:47 UTC
udisks2: LPE via as-user option spoofing in Filesystem.Mount

The org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method accepts an "as-user" option that instructs the udisks daemon to mount a filesystem on behalf of a specified user rather than the calling user. This changes the mount path (typically under /run/media/$USER/) and grants the specified user unmount privileges.

Insufficient authorization checking on the "as-user" option allows a local attacker with an active console session to spoof the as-user parameter, mounting filesystems on behalf of arbitrary users including privileged accounts. This can be used to:

1. Mount attacker-controlled filesystem content under a target user's media directory
2. Manipulate the mount namespace visible to privileged users
3. Achieve local privilege escalation through mount point injection

The vulnerability requires local D-Bus access (typically an active logind session with allow_active authorization) but does not require administrative privileges to exploit.

Affected: udisks2 (storaged-project/udisks) - versions with as-user mount option support.

Comment 2 errata-xmlrpc 2026-08-11 13:09:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:53435 https://access.redhat.com/errata/RHSA-2026:53435