<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:01:01 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:53435 — Important: udisks2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:53435</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: libudisks2, AlmaLinux:10: libudisks2-devel, AlmaLinux:10: udisks2, AlmaLinux:10: udisks2-iscsi, AlmaLinux:10: udisks2-lsm, AlmaLinux:10: udisks2-lvm2&lt;/p&gt;
&lt;p&gt;The Udisks project provides a daemon, tools, and libraries to access and manipulate disks, storage devices, and technologies.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* udisks2: udisks2: Local Privilege Escalation via as-user option spoofing (CVE-2026-7867)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: libudisks2, AlmaLinux:10: libudisks2-devel, AlmaLinux:10: udisks2, AlmaLinux:10: udisks2-iscsi, AlmaLinux:10: udisks2-lsm, AlmaLinux:10: udisks2-lvm2&lt;/p&gt;
&lt;p&gt;The Udisks project provides a daemon, tools, and libraries to access and manipulate disks, storage devices, and technologies.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* udisks2: udisks2: Local Privilege Escalation via as-user option spoofing (CVE-2026-7867)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:53435</guid>
    </item>
    <item>
      <title>bdu:2026-14235</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14235</link>
      <description>bdu:2026-14235</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14235</guid>
    </item>
    <item>
      <title>EUVD-2026-364427</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364427</link>
      <description>EUVD-2026-364427</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364427</guid>
    </item>
    <item>
      <title>fkie_cve-2026-7867</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-7867</link>
      <description>&lt;p&gt;A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the &amp;#39;as-user&amp;#39; option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the &amp;#39;as-user&amp;#39; parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the &amp;#39;as-user&amp;#39; option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the &amp;#39;as-user&amp;#39; parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-7867</guid>
    </item>
    <item>
      <title>OESA-2026-3460 — udisks2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3460</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: udisks2&lt;/p&gt;
&lt;p&gt;The Udisks project provides a daemon, tools and libraries to access and manipulate disks, storage devices and technologies.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the &amp;amp;apos;as-user&amp;amp;apos; option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the &amp;amp;apos;as-user&amp;amp;apos; parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.(CVE-2026-7867)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: udisks2&lt;/p&gt;
&lt;p&gt;The Udisks project provides a daemon, tools and libraries to access and manipulate disks, storage devices and technologies.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the &amp;amp;apos;as-user&amp;amp;apos; option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the &amp;amp;apos;as-user&amp;amp;apos; parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.(CVE-2026-7867)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3460</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11501-1 — libudisks2-0-2.11.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11501-1</link>
      <description>&lt;p&gt;libudisks2-0-2.11.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libudisks2-0-2.11.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11501-1</guid>
    </item>
    <item>
      <title>RHSA-2026:64798 — Red Hat Security Advisory: udisks2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:64798</link>
      <description>&lt;p&gt;udisks2: udisks2: Local Privilege Escalation via as-user option spoofing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;udisks2: udisks2: Local Privilege Escalation via as-user option spoofing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:64798</guid>
    </item>
    <item>
      <title>RLSA-2026:53435 — Important: udisks2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:53435</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: udisks2&lt;/p&gt;
&lt;p&gt;The Udisks project provides a daemon, tools, and libraries to access and manipulate disks, storage devices, and technologies.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* udisks2: udisks2: Local Privilege Escalation via as-user option spoofing (CVE-2026-7867)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: udisks2&lt;/p&gt;
&lt;p&gt;The Udisks project provides a daemon, tools, and libraries to access and manipulate disks, storage devices, and technologies.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* udisks2: udisks2: Local Privilege Escalation via as-user option spoofing (CVE-2026-7867)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:53435</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23405-1 — Security update for udisks2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23405-1</link>
      <description>&lt;p&gt;Security update for udisks2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for udisks2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23405-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-7867</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-7867</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: udisks2, Ubuntu:26.04:LTS: udisks2&lt;/p&gt;
&lt;p&gt;A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the &amp;#39;as-user&amp;#39; option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the &amp;#39;as-user&amp;#39; parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: udisks2, Ubuntu:26.04:LTS: udisks2&lt;/p&gt;
&lt;p&gt;A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the &amp;#39;as-user&amp;#39; option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the &amp;#39;as-user&amp;#39; parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-7867</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2760 — Red Hat Enterprise Linux (udisks2): Schwachstelle ermöglicht Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2760</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2760</guid>
    </item>
  </channel>
</rss>
