Bug 2512108 - CVE-2026-7867 udisks2: udisks2: Local Privilege Escalation via as-user option spoofing [fedora-all]
Summary: CVE-2026-7867 udisks2: udisks2: Local Privilege Escalation via as-user option...
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: udisks2
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Tomáš Bžatek
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["e16123ac-1c63-460d-ac28-d...
Depends On:
Blocks: CVE-2026-7867
TreeView+ depends on / blocked
 
Reported: 2026-08-06 15:28 UTC by Avinash Hanwate
Modified: 2026-08-06 15:55 UTC (History)
3 users (show)

Fixed In Version: udisks2-2.11.2-1.fc45
Clone Of:
Environment:
Last Closed: 2026-08-06 15:55:16 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Avinash Hanwate 2026-08-06 15:28:42 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Imported from Jira PSIRTSUPT-7383.
Reporter (Jira): Azizcan Dastan

--- Description ---
udisks2: LPE via as-user option spoofing in Filesystem.Mount

The org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method accepts an "as-user" option that instructs the udisks daemon to mount a filesystem on behalf of a specified user rather than the calling user. This changes the mount path (typically under /run/media/$USER/) and grants the specified user unmount privileges.

Insufficient authorization checking on the "as-user" option allows a local attacker with an active console session to spoof the as-user parameter, mounting filesystems on behalf of arbitrary users including privileged accounts. This can be used to:

1. Mount attacker-controlled filesystem content under a target user's media directory
2. Manipulate the mount namespace visible to privileged users
3. Achieve local privilege escalation through mount point injection

The vulnerability requires local D-Bus access (typically an active logind session with allow_active authorization) but does not require administrative privileges to exploit.

Affected: udisks2 (storaged-project/udisks) - versions with as-user mount option support.

This is an embargoed vulnerability reported via Red Hat PSIRT JSM queue.

Comment 1 Tomáš Bžatek 2026-08-06 15:55:16 UTC
Built as:
 udisks2-2.11.2-1.fc45
 udisks2-2.11.2-1.fc44
 udisks2-2.11.2-1.fc43


Note You need to log in before you can comment on or make changes to this bug.