Missing Authorization in udisks - CVE-2026-7867
Published: August 9, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to missing authorization in the Filesystem.Mount D-Bus method handler when processing a caller-controlled as-user option for fstab-managed block devices. A local user can supply a spoofed as-user value to escalate privileges.
Exploitation requires an fstab entry for a udisks2-visible block device with at least one of the x-udisks-auth, user, or users mount options.
Affected software
Debian Linux
udisks2 (Debian package)
How to mitigate CVE-2026-7867
udisks2 (Debian package) - update to 2.10.1-12.1+deb13u2