Canonical AccountsService是英国Canonical公司开源的一个提供用户账户信息查询与操作的系统服务。 Canonical AccountsService 23.13.9-8ubuntu7之前版本存在权限许可和访问控制问题漏洞,该漏洞源于在启动语言辅助脚本时仅部分撤销权限,保留了实际UID为0(root),可能导致本地权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Canonical | accountsservice | 22.07.5-2ubuntu1< 22.07.5-2ubuntu1.6 |
affected |
23.13.9-2ubuntu6< 23.13.9-2ubuntu6.1 |
affected | ||
23.13.9-8ubuntu5< 23.13.9-8ubuntu5.2 |
affected | ||
23.13.9-8ubuntu6< 23.13.9-8ubuntu7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Canonical | accountsservice | 22.07.5-2ubuntu1 ~ 22.07.5-2ubuntu1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61898 | 7.8 HIGH | accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu lang |
| CVE-2026-77113 | 6.7 MEDIUM | Path Traversal Vulnerability in apport-unpack |
No comments yet