该漏洞描述信息的中文翻译如下: Ubuntu 专属补丁对 AccountsService(版本低于 23.13.9-8ubuntu7)进行修复时,仅在启动语言辅助脚本前部分地降低了权限。该补丁将进程的有效用户 ID(effective UID)和有效组 ID(effective GID)更改为目标用户,但保留实际用户 ID(real UID)为 0(即 root 权限)。由辅助脚本生成的 shell 会继承 ruid=0,并可能将其有效用户 ID 重置为 root,从而导致本地权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Canonical | accountsservice | 22.07.5-2ubuntu1< 22.07.5-2ubuntu1.6 |
affected |
23.13.9-2ubuntu6< 23.13.9-2ubuntu6.1 |
affected | ||
23.13.9-8ubuntu5< 23.13.9-8ubuntu5.2 |
affected | ||
23.13.9-8ubuntu6< 23.13.9-8ubuntu7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Canonical | accountsservice | 22.07.5-2ubuntu1 ~ 22.07.5-2ubuntu1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61898 | 7.8 HIGH | accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu lang |
| CVE-2026-77113 | 6.7 MEDIUM | Path Traversal Vulnerability in apport-unpack |
No comments yet