DSA-6414-1 udisks2 - security update
The following vulnerability has been discovered in the UDisks storage daemon: CVE-2026-7867 Azizcan Dastan and Ozlem Ozan discovered a local privilege escalation vulnerability in udisks2 involving the Filesystem.Mount D-Bus method. Using the 'as-user' option, an unprivileged local user can in some cases influence the mount execution path so that a filesystem mount is performed in a privileged/root context without the expected PolicyKit authorization behavior. https://security-tracker.debian.org/tracker/DSA-6414-1
CSIRTS triage
- What
- Local privilege escalation in UDisks2 Filesystem.Mount D-Bus method via 'as-user' option allows unprivileged user to bypass PolicyKit authorization.
- Who is affected
- Systems running vulnerable UDisks2 with unprivileged local users.
- Urgency
- High urgency for systems with untrusted local users; privilege escalation is directly exploitable.
- Action
- Apply Debian DSA-6414-1 security update to UDisks2.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch UDisks2
Get an email when a new UDisks2 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00325.html
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-7867 | coverage & exploitation status | NVD · CVE.org |
More from Debian Security Advisories
- unknownDSA-6415-1 linux - security update2026-08-06
- unknownDSA-6413-1 libde265 - security update2026-08-06
- unknownDSA-6412-1 botan3 - security update2026-08-05
- unknownDSA-6411-1 aom - security update2026-08-05
- unknownDSA-6410-1 libssh - security update2026-08-02