freedesktop accountsservice是freedesktop组织开源的一套系统账户管理工具。 freedesktop accountsservice存在权限许可和访问控制问题漏洞,该漏洞源于systemd-homed的SetIconFile代码路径以root权限打开用户提供的文件名,未执行验证和权限降级操作,可能导致本地攻击者读取accounts-daemon进程可访问的任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-17107 | 8.5 HIGH | Cluster-proxy: impersonation-header injection grants cluster-admin on every managed cluste |
| CVE-2026-66337 | 6.5 MEDIUM | Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_ |
| CVE-2026-66339 | 6.5 MEDIUM | Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization hea |
| CVE-2026-17059 | 6.5 MEDIUM | Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypas |
| CVE-2026-17048 | 5.5 MEDIUM | Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via adm |
| CVE-2026-16730 | 5.5 MEDIUM | Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup |
| CVE-2026-16910 | 5.5 MEDIUM | Quay: ssrf in red hat quay notification webhooks (slack/generic) |
| CVE-2026-66338 | 5.4 MEDIUM | Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_in |
| CVE-2026-17039 | 3.1 LOW | Pki-core: dogtag-pki: redhat-pki: pki-core: ca renewal request processing omits realm auth |
No comments yet