Skip to content
Red HatCVE-2026-7867

Red Hat udisks2: privilege escalation

High7.8CVE-2026-7867 · Published Aug 6, 2026 · updated Sep 8, 2026

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat, Inc.: CVE records (CNA)
Product
>= 2.10.0, < 2.11.22.11.2
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat GStreamer gst-plugins-good: denial of service
High7.5Aug 6
Red Hat SAML broker: capture-replay
Medium6.4Aug 6
Red Hat Enterprise Linux 10: integer overflow
Low2.2Aug 5
Red Hat RPM: buffer overflow
Medium5.5Aug 5
Red Hat OpenShift Container Platform 4: authentication bypass
Medium6.5Aug 5
Red Hat SAML broker: origin validation error
High7.4Aug 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.