7.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created suggestion
accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.
References
-
Launchpad Bug #2157985 issue-tracking
-
Ubuntu CVE Tracker vendor-advisory
Affected products
- <22.07.5-2ubuntu1.6
- <23.13.9-8ubuntu5.2
- <23.13.9-2ubuntu6.1
- <23.13.9-8ubuntu7
Package maintainers
-
@jtojnar Jan Tojnar <jtojnar@gmail.com>
-
@pSub Pascal Wittmann <mail@pascal-wittmann.de>
-
@Hythera Hythera