{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/freedesktop/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-7867"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["udisks2"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Freedesktop"],"content_html":"\u003cp\u003eCVE-2026-7867 describes an authorization bypass vulnerability in udisks2, a core system component responsible for storage management on many Linux distributions. The vulnerability resides within the D-Bus method org.freedesktop.UDisks2.Filesystem.Mount(). A local attacker who maintains an active console session can manipulate the 'as-user' parameter during the mounting process. By providing unauthorized user identifiers to this parameter, an attacker can influence the mount operation to execute within the context of arbitrary, higher-privileged accounts. Successful exploitation grants the attacker the ability to inject mount points and manipulate the mount namespace of privileged users, effectively leading to full local privilege escalation. This issue is particularly critical in multi-user environments or shared workstations where local console access is available to unprivileged users.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-7867 allows an unprivileged local user to escalate their privileges to those of other users, including root or service accounts. The impact involves potential system-wide compromise, unauthorized data access, and persistence through the manipulation of mount configurations. The scope of targeting includes any Linux environment utilizing udisks2 with default configurations where D-Bus access is permitted for local console users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and audit systems running udisks2 using package management logs or inventory tools.\u003c/li\u003e\n\u003cli\u003eMonitor D-Bus communication logs for suspicious calls to org.freedesktop.UDisks2.Filesystem.Mount(), specifically looking for anomalous values passed to the 'as-user' parameter.\u003c/li\u003e\n\u003cli\u003ePatch the udisks2 package to the version provided by the distribution maintainer that addresses CVE-2026-7867.\u003c/li\u003e\n\u003cli\u003eRestrict access to system D-Bus interfaces if not strictly required for local user sessions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T23:33:26Z","date_published":"2026-08-06T23:33:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-udisks2-privesc/","summary":"A local privilege escalation vulnerability in udisks2 allows authenticated console users to bypass authorization checks in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method to mount filesystems as privileged users.","title":"Local Privilege Escalation in udisks2 via D-Bus Mount Injection","url":"https://feed.craftedsignal.io/briefs/2026-08-udisks2-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Freedesktop","version":"https://jsonfeed.org/version/1.1"}